A collection of fragments of understanding in the pursuit of deeper questions.
"It's a law of thermodynamics, and no one has ever witnessed a sustained violation of it." A scientific law is a statement of fact, deduced from observation, to the effect that a particular natural or scientific phenomenon always occurs if certain conditions are present. If the law is violated, it ceases to be a law.
"A referee is appointed to a football game in order to apply the laws of the game". It is a rule defining correct procedure or behavior in a sport. If the law is violated the consequence is losing the game or being expelled.
"All our life we live knowing that God's justice demands satisfaction for our transgression of God's law. The body of divine commandments as expressed in any religious text. The consequence of a violation of the law is sin.
"Shooting the birds is against the law. They were taken to court for breaking the law. The system of rules which a particular community recognizes as regulating the actions of its members. The consequence of the violation of the law is the imposition of penalties.
Legal norms may serve different purposes:
The relationships among members of the same social group are regulatedby several norms, where norms are something that is typical, expected, standard.
The sources of norms are:
Legal norms are produced by the legal system (or rather from those sources that are given system internally recognizes) which have the power of producing binding effects on individuals subject to the system. Unlike other categories of norms, legal norms can be enforced y the state through the imposition of penalties.
The characteristics of legal norms are:
"Everyone who commits first degree murder or second murder is guilty of an indictable offense and shall be sentenced to imprisonment for life".
"Everyone who commits first degree murder or second degree murder is guilty of an indictable offense and shall be sentenced to imprisonment for life".
Identifying legal norms, each legal system has some golden norms which are established by the constitution, which is the institution that identify the different sources in the legal system.
Legal norms can be implemented by the state, which is the social institution entitled to use the force and penalties to assure that laws and rules are followed. Unless there is an entity such as the State, the laws and rules won't be binding on the individuals.
Legal system (ubi societas society, ibi ius laws) there is a strict relation between Social Institutions and the Body of Legal Norms.
Legal system as social institution, constituent elements are:
Classification of legal system
| Fluid and Widespread | Authoritarian or concentrated |
|---|---|
| Voluntary (ex. EU) | Necessary |
| Territorial (If your sovereign power extends to a specific territory, EU) | Non-territorial (WTO) |
| General (goals, such as EU has a general legal system) | Specialized (EU initially started as specialized when trying to establish a unique market |
| Independent (no superior authorities on which the state depends) | Derived (EU, some states decided to form that legal system) |
| Sovereign (generally State are usually sovereign) | Non-sovereign (WTO) |
There is a pluralism of legal systems, the State is only one among the existing legal systems The State has a legal system meeting the following characteristics:
"A legal system having general ends which exercises sovereign powers over a specific territory, to which the subjects belonging to such system are necessarily subordinated " - Costantino Mortati.
Three characterising elements of the State legal system are:
The impact of the Internet on sovereignty,
The concept of people is different from:
Citizenship is a concept identifying the condition of being bound to a given State:
Two criteria are used as distinctive elements to differentiate citizens from aliens:
Forms of State: the relationship between the state that can legitimately exercise coercive power, on one hand, and its citizens, taken individually or as a community, on the other. [to understand the shift of power from public authorities to platforms] So it is a set of values and principles that are behind the relationship behind the State and citizens. ex. Equality is a value that have changed over time, from slavery to inequality between men and women, but the set of values and principles have changed over time in order to achieve equality. There are two different methods:
**Diachronic Method **
Feudal state
Each State is sovereign and has power over a permanent population which is established over a limited territory. Prior to the peace, the organization of the community was feudalism in which there was a total identification of the feudal lord with the possession of the land. The organization of the community was based on private agreements between individuals. And the sole aim was the protection of the lands and its related possessions from external attacks. The lord was giving protection of everyone under his sovereignty, in exchange of services on the land. It cannot considered a State because there is not a complete sovereignty, each feud is independent and there was not the concept of people. People were only workers for a specific purpose, they did not have rights expect from being compensated for the service on the land ⇛ no concept of citizenship. The State has general ends while feudalism didn't.
Absolute State
Shift of power from the feudal lords, to the kings (and thus the stabilization of monarchical authority). Land did not anymore imply power, but money was the actual form of power. The possession of power is proportional to the possession of money. And it has a sovereign power (legislative → make laws, executive → apply the law and make it effective, juridical → enforce the law and make sure it is not violated) resides in the King. In the absolute state the three components of the sovereign power were in the hand to the King. Absolute power means that it has no constraint, and all the powers were resigned in the King and nobody could oppose to it. The general goal was to have money, there is no more the idea of protection of the land. The king is considered the holder of the sovereign power.
Liberal State
It is characterized by the separation of powers based on fact that there is no more the same body holding the three powers but powers are allocated among different and separate authorities. There is a judiciary which exercise juridical power, Parliaments had legislative power most of the time in accordance with the king. There is a limitation of monarchical power. The concept of popular and national sovereignty: the power is under the control of the people which are part of the parliament and have relationship with King.
The introduction of the rule of law is faced all the state activities are subject to law, and implies the separation of the three different power and therefore political power is subject to constraint too. The rule of law is introduced because constitution begin to being signed, which are placing boundaries over bodies which exercise political power. Another feature is the protection of first generation rights (Negative rights are those which do not require the state intervention to be protected but can be fulfilled when the state does not interfere with their enjoyment → ex. the freedom of expression: the state doesn't have to build anything ≠ the right of education: the state has to build schools. ) The individual rights were the first right protected in the first liberal state and for this reason are defined first generation rights. Strong separation between State and society (limited intervention in the economy).
Democratic / Pluralistic State
A shift is faced (only upper classes had rights in the Liberal State) now everybody has rights and there are no more distinctions based on social status. There is the recreation of mass parties, which capture social instances and the political interest rises, therefore political rights are open to everyone. While previously the parties were reserved only to upper classes. There are also social and economic rights and not only first generation rights, which are second generation rights. The attention on social and economic rights led to increase of social welfare in fact Welfare States were born. The State reaches its highest point of sovereign power. Between the democratic and the welfare state some Nations went through a period which is called the totalitarian state ( for example Italy, Germany and Japan). Passage to a multiclass society and the creation of mass parties is faced which increase the participation in the political life of the Nation. Second generation rights are recognized such as education and health care.
Using the synchronic method state look at the current organization of the political power and how it is exercise on the citizens.
Unitary state: there is a central government which has a total legislative power (China).
Decentralized state: sub-state entities are present and exercise some part of the legislative power. For example the United States of America
The distinction is made on the basis of five elements:
Allocation of Legislative Powers in the Italian Constitution Executive legislative power: State Concurring legislation: State and Regions Residual legislation: Regions.
Forms of government Set of rules concerning the distribution of power among the branches of the government (bodies of the central government) Four different forms:
The classification of forms of government is based on three methods:
Parliament - Parliamentary executive It is elected by the electoral body. It has relationship:
The executive needs to have confidence otherwise elections will happen again in order to re-establish the confidence. There is both a head of state and a head of government, there is no popular election of the head of state, so the elections are not direct. The head of state serve for 7 years while the head of government serve for fixed terms (2 normally) if he is able to get to the end.
Presidential executive
Congress has the power of impeachment only in certain circumstances.
The President creates a cabinet, with secretaries of states
**Differences: **
| Parliamentary Executive | Presidential Executive |
|---|---|
| Head of state + Head of government | Head of State and Government are combined into one institution: the President |
| Neither the head of state nor the head of government is popularly elected | The president is popularly elected |
| Generally, the head of government does not serve for a fixed term | The president serves for a fixed term |
Semi-Presidential Executive Electoral body elects both the parliament and the president - which means that he is popularly elected. There is no confidence relationship between the parliament and the president. The parliament votes confidence to the government / cabinet which is appointed by the president.
The executive power is splitted between the president and the government (parliamentary executive the head of state has no political power). The majority in the parliament can shift in a short period of time so the executive power could potentially be exercised by two organs coming from different parties.
Cohabitation: the scenario in which two different parties share executive power. If the situation is not verified the president exercise the complete executive power, while if the political background (cohabitation scenario) is different also the prime minister will have some executive power. The president serves for a fixed term (5 years, it was reduced from 7 in France) [read the Directorial Executive]
The people voted for the Republic. After a constituent Assembly was elected to draft and approve the Constitution of the Republic. Italy lost the World War II and was completely destroyed by the Allied bombings and war. Constitution drafted with the aim to avoid the return of Fascism period. Need to restate rights and freedom after the dark Fascist age. Need to avoid risks of the Communism.
From the Albertine Statute to the Constitution Which signed the passage from a flexible to a rigid constitution: the legal system should be in line with the supreme laws which are the one included in the constitution. The constitution cannot be changed, there are some exception but there is a precise procedure that must be followed over a precise period of time. The rigid constitution is important because it should be maintained and respected over time, and if a change is needed it should be really fundamental.
The Albertine Statute was a flexible constitution allowing the parliament changes just by passing a law.
Constitutions may be:
| Codified - One single document (set of provisions in one single document) | Uncodified (UK, Israel) |
|---|---|
| Long containing the frame of government and the bill of rights (first, second and third rights*) | Short containing the frame of government (France) |
| Flexible formally equal to ordinary laws, therefore the Constitution may be modified an ordinary law | Rigid at the top of the hierarchy of the legal sources therefore modifications require a special amendment procedure |
| Voted drafted and voted by a constituent assembly/ people | Octroyée granted by a monarch |
| * third generation rights = privacy, environment |
**Italian Constitution ** It was made by a special organ that had the role of creating the Constitution. The Italian Constitution is:
**Constitutional Organs **
**Sources of Law in Italy ** Super Primary Sources, have the highest rank in the constitution which is typical of rigid constitutions. Constitutional Laws, are the ones needed to change the Constitution. Law, are primary sources and just they are just below the Constitution. Local regulations, secondary sources.
Constitutional Justice (no study) Constitutional court makes sure that the constitution is not violated or overruled by other law written for primary sources. Check that there are no conflicts between primary sources and constitution otherwise the supremacy of the constitution is violated. The members are elected some by the Parliament (5 members) others are appointed by the president of the Republic (5) and the last from the supreme courts (5). Justices are the members of the constitutional court and they are in charge for 9 years and cannot be re-elected.
Lawmaking process (Not Compulsory) There is a proposal which can either come from the parliament, or the regions, or the citizens, or the CNEL. It is introduced in the chamber or the senate and then in the other organ, it must be approved by both and then the bill is turned in law. The promulgation of the law is the signing of the law by the president. Once the law is published on the Italian Official Journal of Law, it will become effective after 15 days.
**Legislative decrees and Law Decrees ** Legislative Decrees, law that grants to Government the power to issue decrees within specified limits. Such decrees have the same force as the law. Law decrees, the act is different and approved when there are situations of emergencies. The government and the executive approve a law decrees to move the resources to the sector damaged. Within 60 days Parliament shall convert into law, otherwise the cease to be effective. There is no time to wait for the double approvement of the chambers.
Conflicts of law There is a hierarchy of law (Constitution - Super primary - Primary - Secondary). If there is a conflict, which means that the norm has a different meaning or there is contradiction between two rules.
The European Union - The origins After the World War II, 6 countries: Italy, Belgium, France, Western Germany, Netherlands and Luxembourg decided to realize an economic union, aimed at achieving peace after the War.
The European Union - Community Structure Economic Union requires a Political Union in the long term. This Union was established through three communities:
The first two were established with the Treaty of Paris (1951), while the third with the Treat of Rome (1957), which is the one still active, representing the European Community right now.
The European Union - International Organization From a legal perspective the two Treaties are international sources of law, creating obligations to the states, creating the environment for a deeper political integration.
The European Union - Treaties
The European Union - 1985 Schengen Agreement In 1985 was established an agreement, with which more states took part to the European Union, and its purpose was to establish freedom of circulation of individuals, capitals, but the achievement of this economic freedom allowed to abolish border checks between signatory countries.
The European Union - 1992 Maastricht Treaty It was an important treaty in the further economic integration of the states, with the first steps towards the definition of the EURO.
The Lisbon Treaty - Basic Structure of EU Treaties System The Charter of Fundamental Rights of the European Union is based on two pillars that are:
Charter of Fundamental Rights of the EU The Charter consists of 54 articles divided into 7 titles:
EU Institutions
EU Legislative Acts In the European Legal System we can differentiate among:
States have to comply with the binding sources and would occur in problems if they don't follow them.
European Legislative Process - Ordinary Legislative Procedure The legislative initiative rest in the hands of the EU Commission, but legislative power is actually exercised by the EU Parliament and the EU Council, which act as co-legislator.
Council of Europe The Council of Europe (COE) is an intergovernmental organization (47 Member States) devoted to promoting human rights, education and culture. One of its foundational documents is the European Convention for the Protection of Human Rights and Fundamental Freedoms (ECHR).
Some 800 millions of people are actually living under the protection of the ECHR, as a "minimum rule" of human rights protection.
| Council of Europe | European Union |
|---|---|
| International legal order having the specific purpose of protecting human rights | A system designed to ensure peace through economic integration: legal order having general purposes |
| 47 contracting parties (27 of which are EU Member States) | 27 Member States |
| European Convention on Human Rights (“ECHR”) | Charter of Fundamental Rights of the European Union |
| European Court of Human Rights (based in Strasbourg) ensuring the respect of the rights and freedoms enshrined in the ECHR. | Court of Justice of the European Union (based in Luxembourg) ensuring the supremacy of the Treaties and the consistent application of EU law among Member States. |
Europe as Country of Rights
Court of Justice of the European Union The Court of Justice of the European Union has a crucial role in transforming a community based on economic purpose into a second European Human Rights protection system. Fundamental rights were originally meant as the grounds of possible limitations to the economic freedoms set forth in the Treaties (i.e. exceptions). Strong activism in ensuring the respect of fundamental rights both against EU Institutions and the Member States, the role of the Charter. The Court of Justice of the European Union is composed by 27 Justices (one for each member state) and 11 Advocates general. Judges and Advocates General are appointed for a term of office six years (renewable). The Court may sit as a full court, in a Grand Chamber of 15 judges or in Chambers of 3 or 5 judges. The Court sits as a full court in the particular cases prescribed by the Statue of the Court and where the Court considers that a case is of exceptional importance. The Court sits in a Grand Chamber when a Member State or an Institution which is a party to the proceedings so requests, and in particularly complex or important cases. The Court of Justice and the Protection of Fundamental Rights. Primary objective of the Treaties was a union based on economic integration and there was no express provision on human rights. The main problem of the Court is the reconciliation with promotion of fundamental economic freedoms.
The Preliminary Reference, Art. 267 TFEU, "The Court of Justice of the European Union shall have jurisdiction to give preliminary rulings concerning:
The Implications of the preliminary ruling mechanism are:
The European Court of Human Rights The main role of the ECHR is to receive applications from any person, non-governmental organization or group of individuals that claims to be victim of a violation of the rights set forth in the ECHR by one of the Contracting Parties. The European Court of Human Rights is composed of 47 Judges, 1 from each of the Contracting States. Judges are elected for a 9 years non-renewable term. A 3-judges committee may rule on the admissibility of the case. Each Chamber is composed of the President of the relevant Section, the "national judge" and 5 other judges. There exist 5 sections in which Chambers are formed.
Differences between the two Courts - Judicial remedies before the European Courts ECHR, application can be submitted by any citizen of a High Contracting Party [...] only after all the national judicial remedies failed to address the violation Scope of the scrutiny: ruling on alleged violations of the ECHR. Court of Justice of EU, Court of the complex EU system: many functions. Usually not triggered by individual citizens. Proceedings against a Member State for failure to fulfil an obligation. Annulment proceeding. Proceeding for failure to act. Preliminary ruling.
ARPANET - The Origins Sputnik, the first USSR satellite. The US realized that the USSR was more technologically advanced. ARPA (Advanced Researches Projects Agency) was founded with the intent to do researches and find innovative solutions for military purposes, such as the development of a way to securely and immediately exchange information. ARPA created ARPANET in 1969, which principal am was to allow information exchange also in case of nuclear disaster, but also, enhance information exchanges for research purposes. Important role of universities.
ARPANET - The Importance of Nodes The idea of ARPANET was to develop a network made of nodes (hosts) that would allow the communication among them even if one of the nodes would stop working. The development of nodes in the network was facilitated by a mixture between universities and military. However, the U.S. Government decided to split ARPANET in MILNET (to ensure secrecy in military communications) and ARPANET (used by universities to exchange information).
ARPANET - The Need to Have Uniformity Scientists developed Protocols, which sets of rules aimed at allowing communication. The most important one is the TCP/IP.
From ARPANET to INTERNET From the various networks of ARPANET we arrived to a network connecting hosts worldwide, the INTERNET. Each node in the Internet can be connected by different means of connection such as: optical fibres, satellite, radio, infrared, ...
INTERNET - TCP/IP Protocol The protocol used by Internet is the TCP/IP through which one single packet of information is divided in multiple smaller packages, travels singularly in the network towards the destination and the packages are recomposed when the final host is reached.
INTERNET - HTTP Protocol In 1991, while woking at the CERN in Geneva, Tim Berners Lee developed the HTTP Protocol (Hyper Text Transfer Protocol). This protocol allows a Client (browser) to ask a Server 1 an information which is hosted on a Server 2, and this transfer of information is made possible by an hyperlink.
INTERNET - Browser The browser retrieves, presents and transfers information from the World Wide Web in a visible and user-friendly way.
INTERNET - IP Addresses and DNS The IP Address means to clearly identify one computer (host) in the whole network, while the DNS (Domain Name System) is the tool that associates each IP Address with a user-friendly name, to reach that particular host. From which derived the creation of associations/agencies aimed at disciplining the assignment of IPs.
INTERNET - Domain Name System We have a Net of Databases, hence a list of all IP addresses of servers in the network. DNS is useful to facilitate conversion between DNS and IP. Handle the domains which are structure among different levels in the URL address: .it, .com, .net (are first level domains).
INTERNET - Self-regulatory agencies During time, Internet self-regulated itself via several agencies that emerged de facto, which are private entities that handle crucial functions. This brings to the surface a series of problems that are not easily solvable.
INTERNET - Problems with self-regulatory agencies
Internet Regulation - Declaration of the Independence "Governments of the Industrial World, you weary giants of flesh and steel, I come from Cyberspace, the new home of Mind. On behalf of the future, I ask you of the past to leave us alone. You are not welcome among us. You have no sovereignty where we gather" - John Perry Barlow (cyber-libertarian).
Internet Regulation - Sealand Principality Copyright issues in Sweden with the host thepiratebay.org. The website attempted to buy the micro-nation Sealand, in order to escape from prosecution (www.sealandgov.org").
Internet Regulation - Self-Regulation? Often referred to as "cyberanarchy". Simpatized by David Johnson and David Post. They sustained that Cyberspace is a place where distinct laws apply. Necessary for the Internet to govern itself. "Internet Citizens" (users) will obey laws of electronic entities like service providers.
Internet Regulation - External/State-Regulation? Jack Goldsmith and other academics were against the cyberanarchy, sustaining that the activity in cyberspace can be assimilated to transnational activity (Email, Telephone). Traditional legal tools and choice-of-law problems are applicable in the cyberspace. This theory sustains that the States is still the authority that has the jurisdiction, therefore illegal behaviours on the Internet have to be punished by the States.
The problem with the Internet is that it is not clear where the State can apply its Sovereign power. For example, gambling services, activities which have very strict regulations in some countries and less strict in others. Internet has allowed gambling services to expand their access beyond their base-country borders, maybe also in places where gambling is in some way prohibited. This generates a Jurisdictional Issue.
Jurisdiction Three different concepts of "Jurisdiction":
When considering the Internet case, the problems concern mainly the second two types of jurisdiction.
The US Scenario
Pennoyer v. Neff (1878)
The defendant must be brought within a State's jurisdiction by service of process within the state of voluntary appearance: required physical presence. (Individual presence of the person on which you want to apply the law).
International Shoe (1945)
Washington State taxes on an Illinois shoe company? The defendant needs not be present so long as he has certain minimum contacts with the forum so that it does not offend traditional notions of fair play and substantial justice. (There is a reasonable expectation that defendant had a contact on that State, therefore the authorities of that State can claim to have jurisdiction).
How much extensive must a party's contact with a state be for the courts of that state to be able to exercise jurisdiction over that party?
There be some acts by which the defendant purposefully avails itself of the privilege of conducting activities within the forum State, thus invoking the benefits and protections of its laws. (It means that there if you are getting the benefits of trading in one State, then you're subject also to "negatives", such as that State's jurisdiction). Therefore the two "tests" defined for the relationships between States are:
Calder v Jones (1984) A professional entertainer who lived and worked in California and whose television career was centred there started a lawsuit in California, claiming that she had been libeled in an article written and edited by authors in Florida and published in a national magazine having its largest circulation in California. The authors, both residents of Florida, were served with process by mail in Florida, and claimed lack of personal jurisdiction. The Court developed the "Effects Test". There is a reasonable expectation for the defendants to be sued in the forum State: jurisdiction in California is proper because the effects of the Florida conduct were felt there. No physical presence but ... contract
Burger King Corp. v Rudzwicz (1985) Personal jurisdiction is proper even though defendants never went to the forum State because "it is an inescapable fact of modern commercia life that a substantial amount of business is transacted wholely by mail and wire communications across State lines". (Deny of Pennoyer 1878 decision).
The US Scenario - Zippo v Zippo Dot Com (1997) On this occasion, the Court developed the "Sliding Scale Test", the Court tried to state in which situations a forum State can apply jurisdiction over a website.
The problems in the Zippo case Almost all disputed cases were left in the land of "interactivity", where courts were given no guidance except to analyse and weigh the levels of interactivity. The Zippo test followed a one-size-fits-all approach, for all Internet disputes: but Internet disputes come in many different sizes and shapes. It may falsely describe the nature of Internet and computer-related communications: the World has changed!
Internet Regulation - The role of Courts as "substitute" regulators Dow Jones & Company v. Gutnick (HCA)
Hold:
Lewis v. King (EWCA) (2004) The parties both were U.S. citizens and residents, and the offending statements were posted to websites located in the U.S.. Those statements were published in Great Britain, only in the sense that the website on which they appeared could be viewed by readers in Great Britain, and apparently were. Forum shopping/regulatory arbitrage? Different burden of proof. A publication occurs when a message is posted on a website and becomes accessible in the UK: EWCA jurisdiction is proper. There is an initial presumption that the natural or appropriate forum for the trial is the place where the tort is committed; in defamation that would be where the libel was published. However, the more tenuous the Claimant's connection with this jurisdiction the weaker this consideration becomes; in Internet cases the court's discretion will be more "open-textured" so as to give effect to the publisher's choice of a global medium. (The fact that you used the Internet makes you subject to jurisdictions that are outside of the national borders). The judge must consider what is the appropriate forum without any consideration of whether there is a "juridical advantage".
Google Spain - Jurisdiction Mr. Costeja Gonzalez lodged with the Spanish Data Protection Authority a complaint against La Vanguardia, which publishes a daily newspaper with a large circulation and against Google Spain and Google Inc. The complaint was based on the fact that, when an internet user entered Mr. Costeja name in the Google search engine, he would obtain links to two pages of La Vanguardia, of 19 January and 9 March 1998 respectively, on which an announcement mentioning his name appeared for a real-estate auction connected with attachment proceedings for the recovery of social security debts. Google defends himself saying that the data processing part of his work is only done in the U.S., while Google Spain is only interested in the advertising business part. So, by the complaint Costeja Gonzalez, the Spain Court requested:
The Court of Spain asked the European Court of Justice for a clarification of Article 4. With regard to the territorial application of [the Directive]: Must be considered that an "establishment", within the meaning of Article 4(1)(a) exists when any one or more of the following circumstances arise:
In order to satisfy the criterion laid down in that provision, it is necessary that the processing of persona data by the controller be "carried out in the context of the activities" of an establishment of the controller on the territory of a Member State. Google disputes that this is the case since the processing of personal data at issue in the main proceedings is carried out exclusively by Google Inc., which operates Google Search without any intervention on the part of Google Spain; the latter's activity is limited to providing support to the Google group's advertising activity which is separate from its search engine service. In the light of the objective of preventing individuals from being deprived of the protection guaranteed by the Directive, it must be held that the processing of personal data for the purposes of the service of a search engine such as Google Search, which is operated by an undertaking that has its seat in a third State but has an establishment in a Member State, is carried out "in the context of the activities" of that establishment if the latter is intended to promote and sell, in that Member State, advertising space offered by the search engine which serves to make the service offered by that engine profitable. (Therefore EU Law is applicable). In these circumstance, the activities of the operator of the Search engine and those of its establishment situated in the Member State concerned are inextricably linked since the activities relating to the advertising space constitute the means of rendering the search engine at issue economically profitable and that engine is, at the same time, the means enabling those activities to be performed. That being so, it cannot be accepted that the processing of personal data carried out for the purposes of the operation of the search engine should escape the obligations and guarantees laid down by Directive 95/46, which would compromise the directive's effectiveness and the effective complete protection of the fundamental rights and freedoms of natural persons which the directive seeks to ensure.
Defamation Shevill (1995) Art. 5 of Brussels Convention (1968) On jurisdiction and the enforcement of judgments in civil and commercial matters. A person domiciled in a Contracting State may, in another Contracting State, be sued:
... the victim of a libel by a newspaper article distributed in several Contracting States may bring an action for damages against the publisher either before the courts of the Contracting State of the place where the publisher of the defamatory publication is established, which have jurisdiction to award damages for all the harm caused by the defamation, or before the courts of each Contracting State in which the publication was distributed and where the victim claims to have suffered injury to his reputation, which have jurisdiction to rule solely in respect of the harm cause in the State of the court seized. (a person libeled by a newspaper has then two options:
eDate Advertising (2011) ... in the event of an alleged infringement of personality rights by means of content placed online on an internet website, the person who considers that his rights have been infringed has the option of bringing an action for liability, in respect of all the damage caused, either before the courts of the Member State in which the publisher of that content is established or before the courts of the Member State in which the centre of his interests is based. That person may also, instead of an action for liability in respect of all the damage caused, bring his action before the courts of each Member State in the territory of which content placed online is or has been accessible. Those courts have jurisdiction only in respect of the damage cause in the territory of the Member State of the court seized.
Licra vs. Yahoo! A website hosted auctions for the sale of Nazi memorabilia, prohibited under French criminal law. First Amendment, because the sale of Nazi memorabilia is covered by the First Amendment protection. TGI Paris ordered Yahoo! To prevent access to the website from the French territory. Yahoo! challenged the injunction before US courts: jurisdiction of the French court is appropriate (purposeful availment). In addition to the first amendment there is no protection for expressions likely to pose a threat to other fundamental rights enshrined in Western constitutions. Forum shopping and regulatory arbitrage, the problem is the enforcement. The saga before the US Courts: a right to regulate freedom of expression from outside the US?
What does "Freedom of Expression" mean? The universalization of civil and political rights implies that the free expression rights formally cover all communicative activities by any single citizen. The "Declaration of the rights of man and of the Citizen" - France (1789) stated: "The free communication of ideas and opinions is one of the most precious of the rights of man. Every citizen ay, accordingly, speak, write, and print with freedom, but shall be responsible for such abuses of the freedom as shall be defined by law"
The Evolution of the Concept States have assumed a more active role in the regulation of free expression (e.g. audiovisual, communication, protection of pluralism). These regulatory schemes go beyond the original liberal idea of lack of state interference, putting in the hands of public institutions the task to create and foster the conditions for a fair and equal access to information by any citizen (pluralism). The digital era and especially the Internet have introduced new kinds of communicative instruments that have continued to change and decentralize the structure of the public sphere as well as the communications market. From State action to a Transnational/Global regulation?
From Atoms to Bits Absence of explicit provisions concerning freedom of expression on the Internet. A matter of balancing fundamental rights. Courts as "playmakers".
Worldwide Differences
U.S. Supreme Court. Supreme Court, Police Dept. of Chicago vs. Mosley, 408 U.S. 92 (1972) - Justice Thurgood Marshall: "The First Amendment means that government has no power to restrict expression because of its message, its ideas, its subject matter, or its content... our people are guaranteed the right to express any thought, free from government censorship. The essence of this forbidden censorship is content control". Freedom of speech is weighed with other interests such as public order and decency, national security, the rights to reputation, fair trial, ...
Standard of Judicial review:
Restriction to freedom of expression
Hate Speech Insults, slurs or epithets directed to someone within a certain group of people. Supreme Court, Beauharnais vs Illinois, 1952: libel and group libel are not covered under the First Amendment. Supreme Court, Brandenburg vs Ohio, 1969: KKK case, freedom of hate speech unless it is directed to producing an "imminent lawless action".
Reno vs ACLU (1997) The Communication Decency Act (1996) criminalized the online distribution of obscene or indecent materials to any person under 18. The Court ruled it unconstitutional. The restrictions were too vague and lacked the precision required to limit free speech: the concepts of "indecent" and "patently offensive" contents were not appropriately defined.
Ashcroft vs ACLU (2002) Attempt to regulate minors protection online: The Child Online Protection Act (1998). "Material harmful to minors", "any obscene material that, based on community standards, an average person would consider to appeal to a prurient interest". The Court ruled it unconstitutional. COPA failed to meet the standards required to circumscribe free speech limitations.
Ashcroft vs Free Speech Coalition (2002) The Child Pornography Prevention Act (1996) prohibited the diffusion of images that appeared to be minors engaged in sexual activity and any form of speech conveying the impression that the images represented minors involved in sexual conduct. The Court ruled it unconstitutional. The restrictions to the freedom of expression weredisproportionate and overbroad.
Historically, nations on the continent of Europe had a low level of protection for freedom of expression. Ù
Different levels of protection nowadays:
Art. 10 ECHR - Statement of principle (1). Everyone has the right to freedom of expression. This right shall include freedom to hold opinions and to receive and impart information and idea without interference by public authority and regardless of frontiers. This Article shall not prevent States from requiring the licensing of broadcasting, television or cinema enterprises.
Art. 10 ECHR - Limitation to the freedom (2). The exercise of these freedoms, since it carries with it duties and responsibilities, may be subject to such formalities, conditions, restrictions or penalties as are prescribed by law and are necessary in a democratic society, in the interests of national security, territorial integrity or public safety, for the prevention of disorder or crime, for the protection of health or morals, for the protection of the reputation or rights of others, for preventing the disclosure of information received in con dence, or for maintaining the authority and impartiality of the judiciary.
Interferences by public authorities are only allowed under the strict conditions that any restriction or sanction must:
No "Hate Speech" in ECHR Although there is no "hate speech" definition, the European Court of Human Rights has established some parameters.
Two approaches to ban hate speech:
Art. 11 EU Charter of Fundamental Rights Freedom of expression and information
Freedom of Expression in the Italian Constitution Art. 21 of the Italian Constitution A new Constitutional right. Applicable to all forms of communication. Only one express limit: Public Morality.
Other implicit limits to protect a different set of rights (e.g. reputation). ECTHR, Pravoye Delo and Shektel (2011) "The risk of harm posed by content and communications on the Internet to the exercise and enjoyment of human rights and freedoms is certainly higher than that posed by the press."
"Therefore, the policies governing reproduction of material from the printed media and the Internet may differ: the latter undeniably have to be adjusted according to the technology's specific features to secure the protection and promotion of the rights and freedoms concerned."
ECTHR, Delfi vs Estonia (2015) Imposing an online news portal to pay damages for having failed to promptly remove defamatory comments posted by anonymous users does not amount to a violation of right to freedom of expression entrusted to Art. 10 of the ECHR.
How would the CJEU have decided the case?
ECHTHR, MTE vs Hungary (2016) A violation of Article 10 of the ECHR had occurred through the imposition of liability on the applicant providers: no clearly unlawful speech.
A notice-and-take down system is sufficient for balancing the rights and interests of all those involved in a given intermediary liability dispute: while in *Delfi *this rule was found to be inapplicable, as the contested comments constituted hate speech, thus allowing to impose liability on internet news portals when they fail to take measures to remove clearly unlawful comments without delay, no such utterances were found to be at issue in *MTE, *making the imposition of a stricter standard unjustifiable.
CJEU, Scarlet (2010) and Netlog (2012) Protection of copyright must be balanced with:
Freedom of expression seems to play a secondary role compared to the right to data protection and the freedom to conduct business.
The European Approach As opposed to the US view, European courts took a restrictive approach. Freedom of expression enjoys protection as fundamental right "among the others" (non -- absolute right). A downgrading of the consideration attached to FoE in the non-digital environment.
ISP Liability - "Mere private law rules?" The origins of ISP Liability in the US: Section 230 CDA: a free speech standpoint. The DMCA and the influence on the European Union Legal Framework. The evolution of Internet Services: a shifting paradigm of liability?
Consequences on free speech: disinformation and hate speech as "stress test". Service Providers are not delivering a content:
Content Providers, are those providing the content and writing information in the web. The origins of ISP Liability - Pre-Section 230 CDA decisions.
Cubby vs CompuServe CompuServe was an Internet Service Provider, which hosted an online news forum. Cubby alleged that CompuServe was the publisher of third-parties defamatory statements, therefore it should have been held liable. CompuServe did not dispute the defamatory nature of the content. However, during the trial no evidence was presented showing that CompuServe either was aware or should have been aware of the existence of such defamatory content. The Court excluded CompuServe liability, stating that "CompuServe has no more editorial control over such a publication than does a public library, book store, or newsstand, and it would be no more feasible for CompuServe to examine every publication it carries for potentially defamatory statements than it would be for any other distributor to do so". A computerized database is the functional equivalent of a more traditional news vendor, and the inconsistent application of a lower (i.e. stricter) standard of liability to an electronic news distributor than that which is applied to a public library, book store or newsstand would impose an undue burden on the free flow of information: the appropriate standard of liability to be applied is whether CompuServe knew or had reason to know of the allegedly defamatory statements.
Stratton Oakmont vs Prodigy Serv. Stratton Oakmont argued that Prodigy should be considered a "publisher" of anonymous statements posted on its bulletin board. Under the common law of defamation, if Prodigy were considered a publisher, it could be held liable for the statements of the unknown user. Conversely, if it were found to be merely a "distributor," it could not be held liable unless it knew or had reason to know about the allegedly defamatory statements. The plaintiffs pointed to Prodigy's "content guidelines," which stated rules that users were expected to abide by, a software screening program which filtered out offensive language, and the employment of moderators for enforcing the content guidelines. The Court found that such representations and policies were sufficient to treat Prodigy as a publisher The Court distinguished the case from that involving CompuServe, which was found merely to be an "electronic for-profit library" or repository and thus a passive distributor. In particular, the court pointed to Prodigy's creation of an "editorial staff of Board Leaders who have the ability to continually monitor incoming transmissions." The court noted, however, that bulletin boards should normally be considered distributors when they do not exercise significant editorial control, as Prodigy had done.
CDA 230 - The most important law protecting internet speech Interactive Computer Service, any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet and such systems operated or services offered by libraries or educational institutions. Information Content Provider, any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the Internet or any other interactive computer service.
The origins of ISP Liability - The Communications Decency Act (1996) "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider". In passing the Communications Decency Act of 1996 the House explicitly stated its intent to overturn the result reached in the Prodigy case. It precludes courts from claims that would place a computer service provider in a publisher's role. Lawsuits seeking to hold a service provider liable for its exercise of a publisher's traditional editorial functions - such as deciding whether to publish, withdraw, postpone or alter content - are barred.
[...] No provider or user of an interactive computer service shall be held liable on account of
(A) any action voluntarily taken in good faith to restrict access to or availability of material that the provider or user considers to be obscene, lewd, lascivious, filthy, excessively violent, harassing, or otherwise objectionable, whether or not such material is constitutionally protected; or (B) any action taken to enable or make available to information content providers or others the technical means to restrict access to material described in paragraph (1)
The origins of ISP Liability - After the CDA Zeran vs America Online, Inc. Zeran brought an action against AOL, arguing that it unreasonably delayed in removing defamatory messages posted by an unidentified third party, refused to post retractions of those messages, and failed to screen for similar postings thereafter. The district court granted judgment for AOL on the grounds that § 230 CDA bars Zeran's claims. Zeran appealed, arguing that § 230 leaves intact liability for interactive computer service providers who possess notice of defamatory material posted through their services. § 230, however, plainly immunizes computer service providers like AOL from liability for information that originates with third parties. Congress' purpose in providing the § 230 immunity was evident: The amount of information communicated via interactive computer services is staggering. The specter of tort liability in an area of such prolific speech would have an obvious chilling effect. It would be impossible for service providers to screen each of their millions of postings for possible problems. Faced with potential liability for each message republished by their services, interactive computer service providers might choose to severely restrict the number and type of messages posted. Congress considered the weight of the speech interests implicated and chose to immunize service providers to avoid any such restrictive effect.
Reno vs American Civil Liberties Union The CDA also criminalized the online distribution of «obscene» or «indecent» materials to any person under 18 Held: Unconstitutional. The restrictions were too vague and lacked the precision required to limit free speech: the concepts of «indecent» and «patently offensive» content were not appropriately defined. «The CDA lacks the precision that the First Amendment requires when a statute regulates the content of speech. In order to deny minors access to potentially harmful speech, the CDA effectively suppresses a large amount of speech that adults have a constitutional right to receive and to address to one another. That burden on adult speech is unacceptable if less restrictive alternatives would be at least as effective in achieving the legitimate purpose that the statute was enacted to serve». «It is true that we have repeatedly recognized the governmental interest in protecting children from harmful materials. But that interest does not justify an unnecessarily broad suppression of speech addressed to adults. As we have explained, the Government may not reduc[e] the adult population to only what is fit for children». «Radio and television, unlike the Internet, have received the most limited First Amendment protection because warnings could not adequately protect the listener from unexpected program content». «On the Internet, the risk of encountering indecent material by accident is remote because a series of affirmative steps is required to access specific material».
Copyright Enforcement and ISP Liability - The rise of the notice-and-take down regime The Digital Millennium Copyright Act A service provider shall not be liable for monetary relief, or for injunctive or other equitable relief, for infringement of copyright by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider, if the service provider:
ISP Liability in Europe - The E-Commerce Directive Policy to enhance Freedom of Expression
Two pillars:
Mere Conduit Providers (Art. 12) The service provider consists of the mere transmission of information or the mere provision of access to a communications network. The ISP is not liable for the information transmitted if it:
Caching Providers (Art. 13) The service provided consists of the temporarily storage of information. Liability Exemptions apply only if:
Hosting Providers (Art. 14) The service provided consists of the permanent storage of information
Liability Exemptions apply only if:
The Second Pillar, Absence of a General Obligation to Monitor (Art. 15) Member States shall not impose a general obligation on providers to monitor the information which they transmit or store, nor a general obligation actively to seek facts or circumstances indicating illegal activity. Member States may establish obligations for information society service providers promptly to inform the competent public authorities of alleged illegal activities undertaken or information provided by recipients of their service or obligations to communicate to the competent authorities, at their request, information enabling the identification of recipients of their service with whom they have storage agreements.
European and National Trends, the Evolving Liability Regime Applicable to ISP Which assumptions behind the E-Commerce Directive (and Section 230 CDA)? Recital 42: «The exemptions from liability established in this Directive cover only cases where the activity of the information society service provider is limited to the technical process of operating and giving access to a communication network over which information made available by third parties is transmitted or temporarily stored, for the sole purpose of making the transmission more efficient; this activity is of a mere technical, automatic and passive nature, which implies that the information society service provider has neither knowledge of nor control over the information which is transmitted or stored».
The View of the Eu Court of Justice - Active vs Passive Providers Google France In the event that the use of a keyword reproducing or imitating registered trademarks does not constitute a. use which may be prevented by the trade mark proprietor, may the provider of the paid referencing service be regarded as providing an information society service consisting of the storage of information provided by the recipient of the service, within the meaning of Article 14 of Directive 2000/31, so that the provider cannot incur liability before it has been informed by the trade mark proprietor of the unlawful use of the sign by the advertiser? The restriction on liability set out in Article 14(1) of Directive 2000/31 applies to cases '[w]here an information society service is provided that consists of the storage of information provided by a recipient of the service' and means that the provider of such a service cannot be held liable for the data which it has stored at the request of a recipient of that service unless that service provider, after having become aware, because of information supplied by an injured party or otherwise, of the unlawful nature of those data or of activities of that recipient, fails to act expeditiously to remove or to disable access to those data.
The legislature defined the concept of 'information society service' as covering services which are provided (i.) at a distance, (ii.) by means of electronic equipment for the processing and storage of data, (iii.) at the individual request of a recipient of services, and (iv.) normally in return for remuneration. Regard being had to the characteristics of the referencing service at issue in the cases in the main proceedings, the conclusion must be that that service features all of the elements of that definition.
In addition, a referencing service provider transmits information from the recipient of that service, namely the advertiser, over a communications network accessible to internet users and stores, that is to say, holds in memory on its server, certain data, such as the keywords selected by the advertiser, the advertising link and the accompanying commercial message, as well as the address of the advertiser's site. It is further necessary that the conduct of that service provider should be limited to that of an 'intermediary service provider' within the meaning intended by the legislature; it follows from recital 42 in the preamble to Directive 2000/31 that the exemptions from liability established in that directive cover only cases in which the activity of the information society service provider is 'of a mere technical, automatic and passive nature', which implies that that service provider 'has neither knowledge of nor control over the information which is transmitted or stored'.
The mere facts that the referencing service is subject to payment, that Google sets the payment terms or that it provides general information to its clients cannot have the effect of depriving Google of the exemptions from liability.
Likewise, concordance between the keyword selected and the search term entered by an internet user is not sufficient of itself to justify the view that Google has knowledge of, or control over, the data entered into its system by advertisers and stored in memory on its server.
By contrast, the role played by Google in the drafting of the commercial message which accompanies the advertising link or in the establishment or selection of keywords is relevant.
L'Oreal vs eBay Article 14(1) of Directive 2000/31/EC must be interpreted as applying to the operator of an online marketplace where that operator has not played an active role allowing it to have knowledge or control of the data stored. The operator plays such a role when it provides assistance which entails, in particular, optimising the presentation of the offers for sale in question or promoting them. Where the operator of the online marketplace has not played an active role, it nonetheless cannot, in a case which may result in an order to pay damages, rely on the exemption from liability if it was aware of facts or circumstances on the basis of which a diligent economic operator should have realized that the offers for sale in question were unlawful and, in the event of it being so aware, failed to act expeditiously.
*The View of the EU Court of Justice - Ex Ante Monitoring Obligations Scarlet vs SABAM SABAM is the Belgian collecting society which had gone to court asking for the ISP, Scarlet, to monitor and block peer-to-peer transfers of music files which it represented. In 2007, a Belgian court ordered Scarlet, an ISP, to bring to an end the copyright infringements of content of which the applicant was the rightholder, by making it impossible for its customers to send or receive in any way files containing a musical work in SABAM's repertoire by means of peer-to-peer software.
Does EU law permit a national court to issue an injunction against intermediaries whose services are used by a third party to infringe copyright, to order an ISP to install, **for all its customers, in abstracto (preventing measures) **and as a preventive measure, exclusively at the cost of that ISP and for an unlimited period, a system for filtering all electronic communications, both incoming and outgoing, passing via its services, in order to identify on its network the movement of electronic files containing a musical, cinematographic or audio-visual work in respect of which the applicant claims to hold rights, and subsequently to block the transfer of such files?
Such an injunction imposed on the ISP to install the contested filtering system would oblige it to actively monitor all the data relating to each of its customers in order to prevent any future infringement of intellectual-property rights. It follows that that injunction would require the ISP to carry out general monitoring, something which is prohibited by Article 15(1) of Directive 2000/31.
In adopting such injunction, the national court would not be respecting the requirement that a fair balance be struck between the right to intellectual property, on the one hand, and the freedom to conduct business, the right to protection of personal data and the freedom to receive or impart information, on the other.
Facebook Austria vs Eva Glawischnig-Piesczek Ms. Eva Glawischnig-Piesczek, who was a member of the Austrian National Council, chair of the parliamentary party die Grünen (the Greens) and the party's federal spokesperson, applied to the Austrian courts for an injunction to be issued ordering Facebook to bring to an end the publication of a defamatory comment.
As Facebook did not react to her request for that comment to be deleted, Ms. Glawischnig-Piesczek sought an order requiring Facebook to cease publication and/or dissemination of photographs of Ms. Glawischnig-Piesczek if the accompanying message disseminated the same allegations as the comment in question and/or 'equivalent content'.
The Oberster Gerichtshof (Supreme Court of Austria), before which this case was ultimately brought, considered that the statements at issue were intended to damage the reputation of Ms. Glawischnig-Piesczek, to insult her and to defame her.
Having been called upon to adjudicate on the question whether the injunction can also be extended, worldwide, to statements with identical wording and/or having equivalent content of which Facebook is not aware, the Oberster Gerichtshof requested the Court of Justice to interpret the E-Commerce Directive in that context. Ruling: a Member State is not precluded from stopping and preventing an illegal activity, which a Member State's court ruling has considered as such and the prohibition of monitoring obligations does not apply to a specific case.
Such a specific case may be found in a particular piece of information stored by a social network provider at the request of a certain user, the content of which was examined and assessed by a court having jurisdiction in the Member State, which, following its assessment, declared it to be illegal. Given that a social network facilitates the swift flow of information stored between its different users, there is a genuine risk that information which was held to be illegal is subsequently reproduced and shared by another user of that network.
In those circumstances, it is legitimate for the court having jurisdiction to require a host provider to block access to the information stored, the content of which is identical to the content previously declared to be illegal, or to remove that information, irrespective of who requested the storage of that information. In particular, in view of the identical content of the information concerned, the injunction granted for that purpose cannot be regarded as imposing on the host provider an obligation to monitor generally the information which it stores, or a general obligation actively to seek facts or circumstances indicating illegal activity, as provided for in Article 15(1) of Directive 2000/31.
In order for an injunction which is intended to bring an end to an illegal act and to prevent it being repeated, to be capable of achieving those objectives effectively, that injunction must be able to extend to information, the content of which, whilst essentially conveying the same message, is worded slightly differently, because of the words used or their combination, compared with the information whose content was declared to be illegal. Otherwise, the effects of such an injunction could easily be circumvented by the storing of messages which are scarcely different from those which were previously declared to be illegal, which could result in the person concerned having to initiate multiple proceedings in order to bring an end to the conduct of which he/she is a victim.
Article 15(1) of Directive 2000/31 implies that the objective of an injunction consisting, inter alia, of effectively protecting a person's reputation and honour, may not be pursued by imposing an excessive obligation on the host provider.
Therefore, it is important that the equivalent information contains specific elements which are properly identified in the injunction, such as the name of the person concerned by the infringement determined previously, the circumstances in which that infringement was determined and equivalent content to that which was declared to be illegal. Differences in the wording of that equivalent content, compared with the content which was declared to be illegal, must not, in any event, be such as to require the host provider concerned to carry out an independent assessment of that content.
In the view of the CJEU, automated technologies could then seek this information, which does not require further analysis and falls within the specific characteristics of the injunction. Directive 2000/31 does not make provision for any limitation, including a territorial limitation, on the scope of the measures which Member States are entitled to adopt in accordance with that directive: accordingly, it does not preclude those injunction measures from producing effects worldwide.
Directive 2000/31, in particular Article 15(1), must be interpreted as meaning that it does not preclude a court of a Member State from:
The View of the European Court of Human Rights - A more human rights-based standpoint Delfi vs Estonia (2015) Imposing an online news portal to pay damages for having failed to promptly remove defamatory comments posted by anonymous users does not amount to a violation of right to freedom of expression entrusted to Art. 10 of the ECHR.
MTE/Index.hu vs Hungary (2016) MTE and Index.hu Zrt: two Internet news portals in Hungary which published the same article, criticizing two real-estate websites managed by a unique company. In both the news portals, users wrote offensive comments against the real-estate company, which sued MTE and Zrt. Hungary's supreme court upheld the decisions of the lower courts, declaring MTE and Zrt liable for having permitted such offensive and unlawful comments to be published. Ruling: the ECHR stated that Hungarian courts did not properly balance the right to good reputation and the protection of freedom of expression It listed a series of criteria which made it come to that conclusion:
Internet Service Providers - The Italian Legislation In Italy there is a division of providers in three categories:
Internet Service Providers - Notice-and-takedown procedure in Italy When on notice of illegal content or activities, including by receiving service of a take-down order properly issued by the competent Administrative or Judicial Authority... ... hosting providers shall promptly remove access to the relevant infringing content. What does "being on notice" (having actual knowledge) of illegal conduct/content mean for an ISP?
In 2019, the Italian Supreme Court ruled that active providers cannot benefit from the liability exemptions. The Court referred to some signs suggesting that the hosting provider has an active role (not all of these must be present): (i) filtering, (ii) selection, (iii) indexing, (iv) organization, (v)cataloging, (vi) aggregation, (vii) evaluation, (viii) use, (ix) modification, (x) extraction, or (xi) promotion of content. If made in the context of a business-oriented management of the service. The Supreme Court held that, for a provider to become aware, it is not required that the rightholder send a formal cease-and-desist letter: a simple communication suffices. Also, it did not exclude that simple indication of the title of the work could be enough. A URL is required only when "indispensable" to identify the infringing content. The Court also ruled that a notice-and-takedown request imposes on the relevant provider an obligation of 'stay-down', ie to prevent the re-uploading of the same infringing content: it has nothing to do with imposing a general monitoring obligation.
The Google vs Vivi Down Case Factual Background On September 8, 2006 a video showing a disabled student being bullied by three of his schoolmates was posted on Google Video; The video was flagged by many users; Video top ranked within the "funny videos" category; Italian postal police sent a removal notice on November 7, 2006; Removal of the video occurred on the same day. The Public Prosecutor of Milan started the investigations for two charges:
Google's management was placed under investigation. First Instance Court of Milan The judge acquitted all the four executives from the charge of defamation. They had no legal obligation to prevent the defamation by exercising a preventive control over content loaded on Google-video site. The executives were found guilty for privacy violations, given 6-months jail terms. The judge suspended the sentences because they were first-time offenders who had committed a minor crime.
First Instance Court of Milan - Reactions "[] we are deeply troubled by this conviction for another equally important reason. It attacks the very principles of freedom on which the Internet is built. Common sense dictates that only the person who films and uploads a video to a hosting platform could take the steps necessary to protect the privacy and obtain the consent of the people they are filming. European Union law was drafted specifically to give hosting providers a safe harbor from liability so long as they remove illegal content once they are notified of its existence."
Court of Appeals of Milan Two Issues at the Court of Appeals of Milan:
Three relevant relationship to take into account:
Therefore it followed the acquittal from data protection law infringement.
The Supreme Court of Cassation Supreme Court of Cassation entirely confirmed the Court of Appeals of Milan's decision. Google as a hosting provider:
The Court declared that Google is merely an Internet Host Provider. It simply provides an online platform where users can uploadvideos, of which content the users are exclusively in charge (of privacy concerns). Nevertheless, it has to immediately remove unlawful contents in case the authority orders to do so.
Most Important topics:
The Post-truth Era According to the Oxford Dictionary post-truth is an adjective defined as "relating to or denoting circumstances in which objective facts are less influential in shaping public opinion than appeals to emotion and personal belief". Post-truth was the "World of the Year" 2016.
New Phenomena? Fake news and hate speech are not something new. An old and a recent example of fake news:
Characteristics of News online:
The Digital Realm
The Role of Algorithms: the Filter Bubble Effect Pariser, personalized searches and filter bubbles: Filter bubble is "a state of intellectual isolation that can result from personalized searches when a website algorithm selectively guesses what information a user would like to see based on information about the user, such as location, past click-behavior and search history". Negative effect on the marketplace of ideas. Sunstein, confirmation bias, polarization. Fake News There is no legal definition of fake news. According to the Cambridge Dictionary, the notion of fake news include "false stories that appear to be news, spread on the internet or using other media, usually created to influence political views or as a joke".
Fake News - Legal Challenges Against this (uncertain) scenario, some claims emerge:
Hate Speech, in search of definition and meaning
Council Framework Decision 2008/913/JHA of 28 November 2008 on combating certain forms and expressions of racism and xenophobia by means of criminal law. Illegal hate speech is defined as: "the public incitement to violence or hatred on the basis of certain characteristics, including race, colour, religion, descent and national or ethnic origin".
Three main questions
What degree of tolerance is offered by the US and European constitutionalism respectively?
Where to draw the thin red line between fake news and truth?
Whether disinformation is a problem
Marketplace of ideas The emergence of truth is the result of the public confrontation of different points of view, no matter how offensive, wrong or inadequate they may be (Abrams v. United States, 250 US, 616, 630, 1919*)*: "the best test of truth is the power of the thought to get itself accepted in the competition of the market, and that truth is the only ground upon which their wishes safely can be carried out".
The question in every case is whether the words used are used in such circumstances and are of such a nature as to create a clear and present danger that they will bring about the substantive evils that the United States Congress has a right to prevent. It is a question of proximity and degree. When a nation is at war, many things that might be said in time of peace are such a hindrance to its effort that their utterance will not be endured so long as men fight, and that no Court could regard them as protected by any constitutional right (Schenck v. United States, 249 U.S. 47, 1919).
Europe - ECHR Two possible ground for limiting the spread of fake news:
Fake news and the Internet How have courts reacted to the rise of the Internet while protecting freedom of expression?
Europe -> Restrictive USA -> Protective
The Marketplace of Ideas
Defining "Fake News"
Remedy? Transparency
Remedy? Education
Remedy? Law
Fact Checking Algorithms and Digital Platforms Is it possible to argue that the use of fact-checking algorithms, which rank content depending on accuracy or nature, makes digital platforms aware of the hosted content? (Responsabilization of platforms does not mean editorial responsibility)
How to deal with fake news and hate speech online? Three possible drawbacks to take into account:
Public vs Self-Regulatory Solutions Public Regulation
Self-Regulation
Co-Regulation In 2016 the EU adopted the Code of Conduct on countering illegal online hate speech. The Goal was ensuring that requests to remove content are promptly handled. Participation of NGOs and public bodies from across the EU to provide data on how quickly such illegal content was removed.
2018: EU Code of Practice on Disinformation It was called "the so called code of practice" because it was missing of the essential criteria.
A multi-dimensional approach to disinformation: the HLEG on fake news and online disinformation
The threat is disinformation, not "Fake News" "false, inaccurate, or misleading information designed, presented and promoted to intentionally cause public harm or for profit. The risk of harm includes threats to democratic political processes and values, which can specifically target a variety of sectors, such as health, science, education, finance and more". Does not cover issues arising from the creation and dissemination online of illegal content (notably defamation, hate speech, incitement to violence), which are subject to regulatory remedies under EU or national laws. Nor does it cover other forms of deliberate but not misleading distortions of facts such a satire and parody.
Italy has some roots connected to ideas on which Europe is based, that makes impossible to private citizens of privacy in a permanent way.
The Origins of the Right to Privacy Privacy is not born in Europe, but in U.S., even if it's taken very seriously in Europe.
1850-1890: The coming of the "sensationalistic press", favoured by the use of new technologies (handheld camera), increased the intrusions in individuals' private life. 1884: Eastman Kodak Company introduced the "snap camera", which allowed to "take candid photographs in public spaces". Between 1850 and 1890, U.S. newspaper circulation grew by 1,000 percent - from 100 papers with 800,000 readers to 900 papers with more than 8 million readers.
Warren & Brandeis, "Right to Privacy", Harvard Law Review, 1890: From a personal experience (Warren) to a new fundamental right The personal experience of S.D. Warren. The Boston gazette was commenting the nightlife of miss. Warren. Therefore the lawyer didn't want his reputation affected by the behavior of the wife. He wrote an article on Harvard Law Review, where he wrote the theorization of privacy. The idea was the "Right to be left alone" and to avoid intrusion in the personal life.
"The existing law affords a principle from which may be invoked to protect the privacy of the individual from invasion either by the too enterprising press, the photographer, or the possessor of any other modern device for rewording or reproducing scenes or sounds"
Technology, such as Cameras at the time, is something that changes the rules of the game. A change in technology requires a change in the ruling system.
Right to Privacy and Data Protection In relation to technology we can do a basic distinction between:
Nowadays it's a dynamic concept, since there is the possibility to store thousands and thousands of data. It's no more just a static "Don't be inside my house and my spaces", therefore there is no processing of the data, it's just static. In a dynamic approach there is a permanent control and the data it's not forgotten after the journal is throw away, but it's stocked in the databases.
Privacy Laws in the US Fourth Amendment, US Constitution (1791) "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized". The Supreme Court, one century later, changed the interpretation of this amendment, in order to include a privacy protection perspective.
Privacy in the US "Shadow right, it's hidden behind"
Griswold v. Connecticut, the Supreme Court decision that made legal access to birth control the law of the land. The ruling stated that birth control is a matter of privacy, and something to be decided between a woman and her doctor. (It is generally recognized as the predecessor to Roe v. Wade and Lawrence v. Texas). Estelle Griswold, the Executive Director of the Planned Parenthood League of Connecticut, and Dr. C. Lee Buxton had opened a birth control clinic in New Haven in order to test the law in Connecticut which had outlawed birth control, and were subsequently arrested. The case went to the Supreme Court, and it was found that the law violated the 14th amendment, which states, "no state shall make or enforce any law which shall abridge the privileges or immunities of citizens of the United States; nor shall any State deprive any person of life, liberty, or property, without due process of law...nor deny any person the equal protection of the laws."
Roe v. Wade, 410 U.S. 113 (1973) The right of a woman to have an abortion is covered by the right to privacy, even though this right must be balanced with the state's interests to protect prenatal life and women's health.
Lawrence v. Texas, 539 U.S. 558 (2003) Based on the constitutional protection afforded to the right to sexual privacy, the Supreme Court struck down the laws of fourteen states that had imposed criminal penalties for the offense of sodomy.
From the US to Europe Privacy and Data Protection in the European legal order
Right to Privacy in the ECHR Article 8 "There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others."
This article clearly provides a right to be free of unlawful searches, but the Court has given the protection for "private and family life" that this article provides a broad interpretation, taking for instance that prohibition of private consensual homosexual acts violates this article. The protection afforded by Art. 8 ECHR is not without limits. The rights enshrined in paragraph 1 may be interfered with subject to the conditions laid down in paragraph 2. In accordance with this structure of Art.8, the following approach to scrutinizing cases, in which this article may have a bearing, may be taken:
Privacy and Data Protection in the EU
Personal data are defined as "any information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity". The notion processing means "any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction".
Treaty on the functioning of the EU (Art. 16) Everyone has the right to the protection of personal data concerning them (Art. 16).
Charter of Fundamental Rights of the EU Respect for private and family life /Art. 7). Everyone has the right to respect for his or her private and family life, home and communications. Protection of personal data (Art. 8).
From a purely market-oriented perspective:
To a Human Rights Perspective:
Privacy and Data Protection in the EU - Data Protection Directive 95/46/EC GDPR Definitions:
Consent, Data Subject's consent. Any freely given, specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed. (e.g. Lombardy tracing mobile phones, temporary measures taken on reducing the privacy of individuals temporarily without their consent).
Principles:
Data Protection Authorities Transfer to third non-EU Countries Member States shall provide that the transfer to a third country of personal data may take place only if the third country in question ensures an adequate level of protection.
Steps Forward by the CJEU
Data Retention Directive (2006) Data retention means the ways according to which the data is stocked and processed and for how long. The duration of Data retention is important because Data could be very important to carry on investigations, institutions can arrive to the identification of the possible criminals. Also, to prevent terrorism attacks (London 2005).
The Ruling
There are no objective and procedural criteria to establish limits of access to the metadata by the authorities. (According to the Court of Justice there aren't clear procedures, how are they treated, to establish the limits of access to the metadata)
Excessive length of the retention period. (The time is too long, two years, even if the goal to prevents crime is reasonable, it's not proportionated).
The metadata (Art. 5), taken as a whole, allow specific and precise deductions concerning private lives, habits, relationships, movements of the users. Absence of any relationship between the retained data and the serious crimes.
The Directive does not require that the data in question is to be retained within the European Union. On those grounds, the Court rules that the Directive 2006/24/EC is invalid.
Data Retention Saga Continues
Right to Be Forgotten, CJUE, Google Spain (2014) Mr. Costeja Gonzalez (Lawyer practitioner in a law firm) lodged with the Spanish Data Protection Authority a complaint against "La Vanguardia", which publishes a daily newspaper with a large circulation and Google Spain and Google Inc. The complaint was based on the fact that, when an internet user entered Mr Costeja name in the Google search engine, he would obtain links to two pages of La Vanguardia, of 19 January and 9 March 1998 respectively, on which an announcement mentioning his name appeared for a real-estate auction connected with attachment proceedings for the recovery of social security debts. By the complaint Costeja Gonzalez requested:
The complaint was upheld in so far as it was directed against Google Spain and Google Inc.\ The Authority (Agencia Espanola de Proteccion de Datos) considered that operators of search engines are subject to data protection legislation given that they carry out data processing for which they are responsible and act as intermediaries in the information society.
Google Spain/Google, Inc. appealed to the Audiencia Nacional de Madrid. The latter issued an order for reference to the CJEU with the following questions:
Advocate General JAASKINEN (suggesting body that suggest which could be the solution, colored answers show the relation between the advocate general and the court of justice answers.). "The particularly complex and difficult constellation of fundamental rights that this case presents prevents justification for reinforcing the data subjects' legal position under the Directive, and imbuing it with a right to be forgotten. This would entail sacrificing pivotal rights such as freedom of expression and information. I would also discourage the Court from concluding that these conflicting interests could satisfactorily be balanced in individual cases on a case‑by‑case basis, with the judgment to be left to the internet search engine service provider."
Agree Application of EU law, broad interpretation of the notion of 'establishment' and of the words 'in the context of the activities'. 'in the light of the objective of Directive 95/46 of ensuring effective and complete protection of the fundamental rights and freedoms of natural persons, and in particular their right to privacy, with respect to the processing of personal data, those words cannot be interpreted restrictively'.
Article 17 - GDPR (2018) (Ultimate decisions in Europe, still active nowadays).
Art. 25, Directive 95/46/EC (What happens when data is transferred to a country which is not member of the European Union, in order to regulate these differences, the EU Directive introduced some mechanisms allowing the transfer of the Data, the most important option is to rely on the Adequacy decision, a decision approved by the European Commission, by which the competent body afford adequate level of protection, which vary on the nature of the data. The Directive introduced some criterion to evaluate the adequacy of the level of protection).
(In the U.S. there is no federal legislation regarding data-trasnfer, there was only a registry in which companies transferring data had to self-certificate the conditions they were using. In 2000 EU needed something more specific than Directive of 95, due to a huge increase of data transportation. The EU Commission adopted the "Safe Harbour" decision, which was a validation of the self-certification mechanism in use in the U.S.)
Safe Harbour 2000/520/EC: Commission Decision on the adequacy of the protection provided by the safe harbor privacy principles.
Safe Harbour: mechanism of self-certification. Intended for U.S. organizations that process personal data collected in the EU, the Safe Harbor Principles are designed to assist eligible organizations to comply with the EU Data Protection Directive and maintain the privacy and integrity of that data. U.S. companies can opt into the program (I.e. self-certify) as long as they adhere to the 7 principles and 15 frequently asked questions.
(The growing complexity of digital companies in 15 years, made the self-certification method obsolete.
During NSA scandal, a student questioned the security of personal data transferred to the U.S. according to the "Safe Harbour". Data Protection authority said that the mechanism was enough but, the High Court of Ireland started doubting too, therefore it asked to clarification to the Court of Justice and the invalidation of the mechanism on the basis of a violation of Art. 7 and 8 of the Charter, the decision and reasoning of he Court of Justice follows...)
Schrems Case (2015) Schrems asked the DPC to prohibit Facebook Ireland from transferring his personal data to the US. He contended that the law and practice in force in the US did not ensure adequate protection of the personal data against the surveillance activities that were engaged in there by the public authorities.
The DPC rejected the complaint. The High Court held that the mass and undifferentiated accessing of personal data is contrary to the principle of proportionality and the fundamental values protected by the Irish Constitution.
However, the case concerns the implementation of EU law as referred to in Article 51 of the Charter and that the legality of the decision at issue in the main proceedings must therefore be assessed in the light of EU law. According to the High Court, Decision 2000/520 does not satisfy the requirements flowing both from Articles 7 and 8 of the Charter.
Advocate General Bot **"**Article 28 of Directive 95/46/EC, read in light of Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that the existence of a decision adopted by the European Commission on the basis of Article 25(6) does not have the effect of preventing a national supervisory authority from investigating a complaint alleging that a third country does not ensure an adequate level of protection of the personal data transferred and, where appropriate, from suspending the transfer of that data".
**"**Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the Department of Commerce of the United States of America is invalid".
Court of Justice **"**Until the Commission decision is declared invalid by the Court, the Member States and their organs, which include their independent supervisory authorities, admittedly cannot adopt measures contrary to that decision. Measures of the EU institutions are in principle presumed to be lawful and accordingly produce legal effects until such time as they are withdrawn, annulled in an action for annulment or declared invalid following a reference for a preliminary ruling or a plea of illegality. However, a Commission decision adopted pursuant to Article 25(6) of Directive 95/46, such as Decision 2000/520, cannot prevent persons whose personal data have been or could be transferred to a third country from lodging with the national supervisory authorities a claim concerning the protection of their rights and freedoms in regard to the processing of that data. A decision of that nature cannot eliminate or reduce the powers expressly accorded to the national supervisory authorities by Article 8(3) of the Charter and Article 28 of the directive". **"**Neither Article 25(2) of Directive 95/46 nor any other provision of the directive contains a definition of the concept of an adequate level of protection. In particular, Article 25(2) does no more than state that the adequacy of the level of protection afforded by a third country 'shall be assessed in the light of all the circumstances surrounding a data transfer operation or set of data transfer operations' and lists, on a non-exhaustive basis, the circumstances to which consideration must be given carrying out such an assessment"
(No binding definition of "adequate", is a flexible definition on purpose. The general purpose of Directive is to ensure a high level of protection of data. Then the Court starts making some reasonings regarding the level of protection of data abroad, and agree on the fact that data cannot be protected as in Europe, but can be meant as requiring an essentially equivalent level of protection)(Adequacy doesn't mean identity, but an essentially equal level of protection, therefore there is a sort of manipulation and interpretation of the word adequacy from the Court).
"Article 25(6) of Directive 95/46 implements the express obligation laid down in Article 8(1) of the Charter to protect personal data and is intended to ensure that the high level of that protection continues where personal data is transferred to a third country ...
The word 'adequate' in Article 25(6) of Directive 95/46 admittedly signifies that a third country cannot be required to ensure a level of protection identical to that guaranteed in the EU legal order. However, as the Advocate General has observed in point 141 of his Opinion, the term 'adequate level of protection' must be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of Directive 95/46 read in the light of the Charter. If there were no such requirement, the objective referred to in the previous paragraph of the present judgment would be disregarded".
(Even if the legal norms applicable in the third country are different from EU, those norms must prove, in practice an essentially equivalent level of protection to that guaranteed within the European Union).
"Even though the means to which the third country has recourse for the purpose of ensuring a level of protection may differ from those employed within the European Union those means must nevertheless prove, in practice, effective in order to ensure protection essentially equivalent to that guaranteed within the European Union.
Also, in the light of the fact that the level of protection ensured by a third country is liable to change, it is incumbent upon the Commission, after it has adopted a decision to check periodically whether the finding relating to the adequacy of the level of protection ensured by the third country is still factually and legally justified. Such a check is required, in any event, when evidence gives rise to a doubt in that regard".
(Since the technology is changing, the Court said that there must be a regular check from the European Commission whether the finding relating to the adequacy of the level of protection ensured by the third country is still factually and legally justified. On both sides, if EU Law changes either third countries' law changes).
"Decision 2000/520 lays down that 'national security, public interest, or law enforcement requirements' have primacy over the safe harbour principles, primacy pursuant to which self-certified US organisations receiving personal data from the EU are bound to disregard those principles without limitation where they conflict with those requirements and therefore prove incompatible with them.
In addition, it does not contain any finding regarding the existence, in the US, of rules intended to limit any interference with the fundamental rights of the persons whose data is transferred from the EU, interference which the State entities of that country would be authorised to engage in when they pursue legitimate objectives, such as national security. Nor does Decision 2000/520 refer to the existence of effective legal protection against interference of that kind".
(The EU Court wanted the data to be safe also from the government's interference).
"Legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life, as guaranteed by Article 7 of the Charter. Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter".
Therefore Decision 2000/520 is invalid. (October 2015) (What happened the day after?)
Transfer of Personal Data to Third Countries
The following are alternatives
Binding Corporate Rules are rules that can be equalized internal policies adopted by multinational group of companies which define its global policy with regard to the international transfers of personal data within the same corporate group to entities located in countries which do not provide an adequate level of protection. (They require a long time to be approved and enter in function). Furthermore, no transfer can be made on this basis outside the group.
Standard Contractual Clauses are set of clauses (approved by the EU Commission) that can be adopted in the agreements between different subjects, however they are quite rigid.
Data Subject Consent
The aftermath of the Schrems Judgment The Judicial Redress Act affords persons whose data are shared by EU and other countries with US law enforcement agencies for the purpose of investigating, detecting, or prosecuting criminal offenses - including citizens of EU Member States - access to civil remedies for certain violations of those protections, and access to court proceedings in which those remedies can be pursued.
Privacy Shield In 2016, the Privacy Shield substituted the Safe Harbour mechanism. "While the US and the EU share the goal of enhancing privacy protection, the US takes a different approach to privacy from that taken by the EU. The US uses a sectoral approach that relies on a mix of legislation, regulation, and self-regulation. Given those differences and to provide organizations in the US with a reliable mechanism for personal data transfers to the US from the EU while ensuring that EU data subjects continue to benefit from effective safeguards and protection as required by European legislation with respect to the processing of their personal data when they have been transferred to non-EU countries, the Department of Commerce is issuing these Privacy Shield Principles".
EU GDPR - Timeline
An Overview
From a Directive to a Regulation?
(There are some specific areas of GDPR where States have margin to adopt some more specific provisions.) Lawfulness of processing - Article 6(2) GDPR
*Member States may **maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points (c) and (e) ***[see below] by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations.
(c) processing is necessary for compliance with a legal obligation to which the controller is subject; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
Member States may provide by law for a lower age for those purposes (16) provided that such lower age is not below 13 years. (Member States can lower the age of 16, but they can't go under 13).
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
Paragraph 1 shall not apply if one of the following applies: processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;
Scope of Application
Material Scope (Art. 2 GDPR)
Territorial Scope (Art. 3 GDPR) The GDPR applies:
to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not [Google Spain].
to the processing of data of data subjects located in the EU by a controller or processor not established in the EU, where the processing activities are related to:
by a controller not established in the Union, but in a place where Member States' national law applies by virtue of public international law.
Personal and Non-Personal Data Personal Data: any information relating to an identified or identifiable natural person (Data Subject). Processing of Personal Data: any operation performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, ... .
The principles of data protection should apply to any information concerning an identified or identifiable natural person. (The GDPR is applicable not only to information directly related to an identified person, but also to information that makes the person identifiable, such as IP Address).
Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person.
To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used either by the controller or by another person to identify the natural person directly or indirectly.
To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.
Pseudonymisation (Even with pseudonymization the GDPR is still applicable)
Anonymization (GDPR is not applicable)
Controller: the natural or legal person, public authority, agency or any other body which determines the purposes and means of the processing of personal data. Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller. (Processor is not acting by himself, but he is following the decisions of the controllers).
Principles
Lawfulness of Processing Main legal basis to process personal data is the Consent, which consists of:
Consent is not required when the processing is necessary to:
(Risk base approach, depending on the entity processing data (Hospitals, social networks, small online shops, the control has to be different according to the quantity and risk assessed).
Processing of Personal Data
Data Subject - Rights
Data Controller/Processor - Obligations
Right to Access
Right to Rectification (and Integration)
Right to Erasure The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay.
Right to Restriction of Processing (You're not interested in the erasure of information, but you are asking for a restriction of information) The data subject shall have the right to obtain from the controller restriction of processing where:
But: with the exception of storage, personal data shall only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.
Right to Object (Similar to the right to erasure, you object that there has never been the consent to process data). The data subject shall have the right to object, on ground relating to his or her particular situation, at any time to the processing of personal data concerning him or her where processing is necessary for:
The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
Right to Object, the case of direct marketing Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
Right to Data Portability (Important) The data subject shall have the right to receive the personal data concerning him or her, in a structured, commonly used and machine-readable format and have the right to transmit those data from the controller to a new controller, without hindrance (Without suffering any negative effect/obstacle), where:
Automated Individual Decision-Making, including Profiling The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The right does not apply where the processing:
Risk-Based Approach
Data Protection by Design and by Default - Art. 25 GDPR Controllers must ensure that, both in the planning phase of processing activities and the implementation phase of any new product or service, data protection principles, and appropriate safeguards, are addressed and implemented.
Compliance with data protection law should not be an after-thought, but should be treated as a key issue in the planning and implementation of any new product or service that affects personal data.
Security of Processing Must be taken into account:
The controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia:
![]() |
![]() |
|---|
In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful:
Data Breach
Data Breach Notification In the case of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority. Unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.
Data Breach Communication In the case of a personal data breach without undue delay and, where feasible**, not later than 72 hours** after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority and, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. The controller shall communicate the personal data breach to the data subject without undue delay.
Records of Processing Activities Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller.
Exemptions from the obligation to keep record of processing activities The obligation does not apply to an enterprise or an organization employing fewer than 250 persons, unless:
DPIA (Data Protection Impact Assessment) A DPIA is a process designed to:
DPIAs are important tools for accountability, as they help controllers to comply with GDPR requirments and to demonstrate that appropriate measures have been taken to ensure compliance (a process for building and demonstrating compliance).
(You conduct an assessment to define which is the risk, if you realize that the specific data processing has high risk, you have to ask to the supervisory authority consultation on the process of data processing).
Supervisory authorities shall establish and make public a list of the kind of processing operations which are subject to the requirement for a DPIA and of the kind of processing operations for which no DPIA is required.
Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, the controller shall consult the supervisory authority prior to processing. If the supervisory authority finds that the intended processing would infringe the GDPR, in particular where the controller has insufficiently identified or mitigated the risk, it shall, within up to eight weeks of receipt of the request for consultation (extended by six weeks, taking into account the complexity of the intended processing), provide written advice to the controller and, where applicable, to the processor. Those periods may be suspended until the supervisory authority has obtained information it has requested for the purposes of the consultation. Member State may in any case require controllers to consult with, and obtain prior authorisation from, the supervisory authority in relation to processing by a controller for the performance of a task carried out by the controller in the public interest, including processing in relation to social protection and public health.
Designation of the DPO (Data Protection Officer) The controller and the processor shall designate a data protection officer in any case where:
Who is the DPO? The DPO shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks provided by Article 39 GDPR. The DPO may be a staff member of the controller or processor, or fulfill the tasks on the basis of a service contract. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority. (Contact point between data controllers/processors and supervisory authorities)
Position of the DPO
Transfer of Personal Data to Third Countries (Nothing changed from the Directive 95/46 to the GDPR)
Penalties "In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine". "Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Those criminal penalties may also allow for the deprivation of the profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice".
Three possible "layers"
There exist two types of administrative fines:
What is e-Privacy? The exchange of information through public electronic communication services, such as the internet and mobile and landline telephony and via their accompanying networks, requires specific rules and safeguards to ensure the service and that network users' right to privacy and confidentiality are respected.
The e-Privacy Directive The Electronic Privacy Directive (2002/58) was drafted specifically to address the requirements of new digital technologies, ease the advance of electronic communications services and create favourable market conditions for the digital economy. The subject of the directive is the «right to privacy in the electronic communications sector» and «free movement of data, communication equipment and services». It was designed to complement the data protection rules and other rules on telecoms.
Scope of application of the e-Privacy Directive
The e-Privacy Directive The Directive sets out rules to:
Key Provisions of the e-Privacy Directive Providers of electronic communication services must secure their services by at least:
Prior User Consent is required in a number of situations, including:
EU Member States are required to have a system of penalties including legal sanctions for infringements of the Directive.
The scope of the rights and obligations can only be restricted by national legislative measures when such restrictions are necessary and proportionate to safeguard specific public interests, such as to allow criminal investigations or to safeguard national security, defense or public security.
Relationship with GDPR GDPR gives effect to art. 8 of the EU Charter (right to data protection) v. e-Privacy Regulation gives effect to art. 7 of the Charter (right to privacy and respect of private life). E-Privacy Regulation is intended to complement and enhance the GDPR rules. E-Privacy constitutes lex specialis to GDPR. (meaning that this is a law which regulates a specific domain, electronic communication service, while the GDPR is still applicable, however the privacy framework will contain some more specific rules to apply in these situations), (lex specialis derogate generali). Recital 175: This regulation should apply to all matters [...] which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC [...] In order to clarify the relationship between this regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this regulation. Art. 95: This regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.
Proposed e-Privacy Regulation: where are we?
Proposed e-Privacy Regulation: key provisions
Applies to communication content and metadata (e.g. time of a call, location), which have a high privacy component and must be anonymized or deleted if users did not give their consent, unless the data is needed for billing. Main contentious issues:
Cookie Law
Rules guaranteeing privacy for content and metadata on electronic communications
Rules Protecting against SPAM
Stronger and more effective enforcement
The European Electronic Communications Code
Focus: Cookies Planet49 case: ECJ Judgment of 1 October 2019. Case concerned the placing of cookies with the purpose of online tracking for behavioral advertising as a condition to access an online service (online lottery). The Directive has led to disparate approaches from national transposition laws and supervisory authorities.
The Cybersecurity Framework Cybersecurity ensures the security of network and information systems. It consists of the protection of internet-connected systems, including hardware, software and data, from different types of cyberattacks.
The challenges of cybersecurity
EU's strategic priorities on cybersecurity
Cyber Resilience EU's approach:
Cyber Crime Cybercrime is one of the fastest growing types of crime: it is high-profit and low-risk. Criminals often exploit anonymity of website domains. It can severely hamper the economy and national/regional plans of economic growth. Crimes specific to the Internet, such as attacks against information systems or phishing (e.g. fake bank websites to solicit passwords enabling access to victims' bank accounts). Online fraud and forgery. Large-scale fraud can be committed online through instruments such as identity theft, phishing, spam and malicious code. Illegal online content, including child sexual abuse material, incitement to racial hatred, incitement to terrorist acts and glorification of violence, terrorism, racism and xenophobia.
Cyber Defense Policy and Capabilities Related to the Common Security and Defense Policy (CSDP). EU Agency for Network and Information Security (ENISA)
The NIS Directive In this directive, the EU, for the first time, tried to create a cooperation among European countries in facing cybersecurity attacks and emergencies. Key Definitions:
Improve National Cybersecurity Capabilities EU Member States must:
National competent authorities monitoring obligations
Computer-security incident response teams (CSIRTs) Responsibilities:
Security and Notification Requirements
Improving EU-level Cooperation
Penalties
The Cybersecurity Act (2017) It introduces a new approach mainly focused on the certification sector.
European cybersecurity certification framework:
Blockchain and the law What is blockchain?
It has the ability to decentralize business models, forms of human interaction and markets. It can be used for record keeping, transferring value and smart contracts to automatically execute transactions: #trust. The legal standpoint and disruptive technologies. Two normative objectives: fundamental right protection vis-à-vis promotion of innovation.
Blockchain(s)
Nodes
Blockchain(s)
GDPR vs Blockchains
Blockchain does not provide any privacy and guarantee regarding the data, therefore some measures have to be implemented.
Personal Data and Blockchain
(GDPR is still applicable on pseudo-anonymized data because even if the data is encrypted through hash, it isn't an irreversible process, there is still the possibility to go back to decrypted data). The only way to escape GDPR is to move data off chain.
Data Controller
Territorial Scope of Application
Enforcement of the GDPR rights
Blockchain and the GDPR
Artificial Intelligence There are many issues related to AI and which are similar to the one relative to blockchain. Those are not only related to the GDPR even though the processing of personal data in artificial intelligence systems is a very debated issue. There are many opinions of this since the automated decision-making processing is something which is developing rapidly, and for this reason in Europe there is a specific provision preventing entirely automated decision systems to affect human rights. (art. 32 of the GDPR). Therefore, algorithms and AI might entail the processing of data and create some challenges. However, the most debate issue regard civil liabilities connected to the damages caused by the usage of AI systems. But there is not a provision giving specific rules. Even if more and more machines will learn how to carry out different activities risks are always involved not only on the instruction received but also regarding the inputs that the machines receive. The challenge is to make sure that AI systems are working more like men rather than "animals"/resilient machines, they should develop skills and new functions. The problems arise when the source of the input of the machine is not known or if the input is based on the experience of the AI machine. Then, who is responsible of the harm in front of the law for an AI system?
It depends also which tradeoff between human right protection and innovation we want to follow:
In general, there are two possible options:
Product liability might be based on
Both options can be considered controversial. With the negligence option you are discouraging those who wants to use and implement AI systems since you are liable only if you violate a duty of care and you undermine the protection of the possible victims. In the other case you are providing the strongest protection to victims, so the manufacturer has no incentives to implement a AI system since he is always liable even if it is not his fault.
another problem: Machine Learning It is not easy to allocate liabilities when you do not have something which is not executed as a result of an input given the manufacture. There is a divergence between the preconstructed behaviour and the behaviour experience, it can create harm. The users should have the responsibility of making sure that the machine is learning in a proper way. But there are also some liability regimes proposed by experts/commentators :
From Napster to Tech Giants From an environment where providers were passive, to an active position.
As from the e-Commerce Directive to the Digital Single Market Strategy. We are moving from a Directive centered principally on the economical aspect, to a fundamental rights dimension.
The Digital Single Market This strategy was based in the need of ruling platforms. There are 3 pillars of Digital Single Market Strategy:
The DSM is important because the digital environment is pervading our society. It's not just an economic reason, the role of fundamental rights and the ECJ in shaping platforms responsibilities (e.g. Delfi case, Scarlet case). (shift of paradigm).
The Digital Single Market: the future of ISP in Europe This 3 documents are not binding, are more intended to make clear the goals of DSM:
(We need a new framework in which platforms are more responsible, protecting core values; to achieve this purpose they will follow a transparent and fair approach).
Internet Service Providers
General rule: liability exception for ISPs as far as they act as intermediaries (service providers) and not as content providers.
(Platforms take editorial decision on content that does not create but manages).
(We are not dealing with personal data processing (GDPR), but we are dealing with content, there are some intersections between the two of course).
Reforms of ISP Liability The system of the e-Commerce Directive has not been repealed.
A new role for online platforms? (or content sharing providers)
Use of protected content by online content-sharing service providers
An online content-sharing service provider shall therefore obtain an authorisation from the rightholders referred to in Article 3(1) and (2) of Directive 2001/29/EC, for instance by concluding a licensing agreement, in order to communicate to the public or make available to the public works or other subject matter."
The first subparagraph of this paragraph shall not affect the possible application of Article 14(1) of Directive 2000/31/EC to those service providers for purposes falling outside the scope of this Directive".
(The Directive here is taking into consideration the Proportionality).
Art. 17 (6), "Member States shall provide that, in respect of new online content-sharing service providers the services of which have been available to the public in the Union for less than three years and which have an annual turnover below EUR 10 million, calculated in accordance with Commission Recommendation 2003/361/EC, the conditions under the liability regime set out in paragraph 4 are limited to compliance with point (a) of paragraph 4 and to acting expeditiously, upon receiving a sufficiently substantiated notice, to disable access to the notified works or other subject matter or to remove those works or other subject matter from their websites. Where the average number of monthly unique visitors of such service providers exceeds 5 million, calculated on the basis of the previous calendar year, they shall also demonstrate that they have made best efforts to prevent further uploads of the notified works and other subject matter for which the rightsholders have provided relevant and necessary information."
Directive 2018/108 - Audiovisual Media Service Directive (Applied)
A new legal framework?
Recital 1, "New types of content, such as video clips or user-generated content, have gained an increasing importance and new players, including providers of video-on-demand services and video-sharing platforms, are now well-established. This convergence of media requires an updated legal framework in order to reflect developments in the market and to achieve a balance between access to online content services, consumer protection and competitiveness."
Art. 1 (1) (aa), "Video-sharing platform service" means a service as defined by Articles 56 and 57 of the Treaty on the Functioning of the European Union, where the principal purpose of the service or of a dissociable section thereof or an essential functionality of the service is devoted to providing programmes, user-generated videos, or both, to the general public, for which the video-sharing platform provider does not have editorial responsibility, in order to inform, entertain or educate, by means of electronic communications networks within the meaning of point (a) of Article 2 of Directive 2002/21/EC and the organisation of which is determined by the video-sharing platform provider, including by automatic means or algorithms in particular by displaying, tagging and sequencing."
(A video sharing platform has not editorial responsibility, YouTube is mainly a video-sharing platform, while Netflix is a content provider and has editorial responsibility).
Applicable Provisions, Art. 28 (b) (1), Without prejudice to Articles 12 to 15 of Directive 2000/31/EC, Member States shall ensure that video-sharing platform providers under their jurisdiction take appropriate measures to protect:
Applicable Provisions, Art. 28 (b) (3), "For the purposes of paragraphs 1 and 2, the appropriate measures shall be determined in light of the nature of the content in question, the harm it may cause, the characteristics of the category of persons to be protected as well as the rights and legitimate interests at stake, including those of the video-sharing platform providers and the users having created or uploaded the content as well as the general public interest.
*Those measures shall be practicable and proportionate, taking into account the size of the video-sharing platform service and the nature of the service that is provided. Those measures shall not lead to any ex-ante control measures or upload-filtering of content which do not comply with Article 15 of Directive 2000/31/EC."*
Regulation on Terrorism (Proposal)
This Regulation is without prejudice to Directive 2000/31/EC." (The directive still applies, but we still consider also Directive 2000/31/EC, that is e-Commerce Directive still applies).
(This is a clear example of the shift from an economic based regulation, to a fundamental rights one, where the rights play a big role in the decision of content regulation).
Art. 4 (2), Hosting service providers shall remove terrorist content or disable access to it as soon as possible and within one hour from receipt of the removal order.
Art. 6, Without prejudice to Directive (EU) 2018/1808 and Directive 2000/31/EC hosting service providers may take specific measures to protect their services against the public dissemination of terrorist content. The measures shall be effective, targeted and proportionate, paying particular attention to the risk and level of exposure to terrorist content, the fundamental rights of the users, and the fundamental importance of the right to freedom of expression and the freedom to receive and impart information and ideas in an open and democratic society.
Transparency Obligations, Art. 9,
Effective Remedy, Art. 10,
Regulation on e-Evidence (Proposal)
This Regulation lays down the rules under which an authority of a Member State may order a service provider offering services in the Union, to produce or preserve electronic evidence, regardless of the location of data.
"Electronic evidence" means evidence stored in electronic form by or on behalf of a service provider at the time of receipt of a production or preservation order certificate, consisting in stored subscriber data, access data, transactional data and content data.
The Regulation also applies to information society services as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council 44 for which the storage of data is a defining component of the service provided to the user, including social networks, online marketplaces facilitating transactions between their users, and other hosting service providers.
Two models to be compared «In the vocabulary of the Chinese», says the philosopher Byung chul Han, «the term "private sphere" does not appear, which has facilitated the construction of a whole infrastructure for surveillance that is highly effective in containing an epidemic». «Digitalization is a collective thrill beyond individualism. In Europe the systemic use of big data would be, as it happens in Asia, much efficient than to rise again borders and walls. But such systemic use is not possible for the legal regime of protection of fundamental rights in Europe».
Is there a real trade-off between using new technologies to contain the spread of Covid-19 and protecting human rights?
China: Massive Surveillance
(China imposed the more restrictive measures, which proved to be among the more effective).
South Korea: COVID-19 Smart Management System (SMS)
(South Korea was almost ready and had an already organized system to deal with the pandemic, in addition to the fact, that Korea, is the "most connected" country in the world, which allowed the government to strictly control the citizens.)
South Korea: Corona 100
Singapore
"Instead of attempting to tackle the issue of contact tracing by answering the question of 'where,' we address contact tracing by answering the question of 'who', [...] the virus doesn't care where transmission happens; it's only interested in whether there is a hospitable host in close contact" (Jason Bay, Senior Director of Government Digital Services at GovTech).
Israel: HaMagen (The Shield)
Europe, EU law:
Processing shall be lawful only if and to the extent that at least one of the following applies:
Regulates the processing of particular categories of personal data (e.g., data concerning health): «personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited». Paragraph 1 shall not apply if one of the following applies: [...] processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject.
The Debate on Contact Tracing in Europe What do we mean by contact tracing? A variety of options:
The Italian way (modeled on the Singaporean and Israeli paradigms):
EDPB (European Data Protection Board) guidelines
Voluntary Adoption. The systematic and large-scale monitoring of location and/or contacts between natural persons is a grave intrusion into their privacy. It can only be legitimized by relying on a voluntary adoption by the users for each of the respective purposes. This would imply, in particular, that individuals who decide not to or cannot use such applications should not suffer from any disadvantage at all.
Public Nature To ensure accountability, the controller of any contact tracing application should be clearly defined. The EDPB considers that the national health authorities could be the controllers for such application; other controllers may also be envisaged. In any cases, if the deployment of contact tracing apps involves different actors their roles and responsibilities must be clearly established from the outset and be explained to the users.
Purpose Limitation In addition, with regard to the principle of purpose limitation, the purposes must be specific enough to exclude further processing for of the COVID- 19 health crisis (e.g., commercial or law enforcement purposes). Once the objective has been clearly defined, it will be necessary to ensure that the use of personal data is adequate, necessary and proportionate.
Principles In the context of a contact tracing application, careful consideration should be given to the principle of data minimisation and data protection by design and by default:
Contact tracing apps do not require tracking the location of individual users. Instead, proximity data should be used;
As contact tracing applications can function without direct identification of individuals, appropriate measures should be put in place to prevent re-identification;
The collected information should reside on the terminal equipment of the user and only the relevant information should be collected when absolutely necessary.
Legal Basis Furthermore [...] the mere fact that the use of contact-tracing applications takes place on a voluntary basis does not mean that the processing of personal data will necessarily be based on consent. When public authorities provide a service based on a mandate assigned by and in line with requirements laid down by law, it appears that the most relevant legal basis for the processing is the necessity for the performance of a task in the public interest, i.e. Art. 6(1)(e) GDPR. The basis for the processing referred to in article 6(1)(e) shall be laid down by Union or Members State law to which the controller is subject. The purpose of the processing shall be determined in that legal basis or shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Safeguards The legal basis or legislative measure that provides the lawful basis for the use of contact tracing applications should, however, incorporate meaningful safeguards including a reference to the voluntary nature of the application. A clear specification of purpose and explicit limitations concerning the further use of personal data should be included, as well as a clear identification of the controller(s) involved. The categories of data as well as the entities to (and purposes for) which, the personal data may be disclosed should also be identified. Depending on the level of interference, additional safeguards should be incorporated, taking into account the nature, scope and purposes of the processing. Finally, the EDPB also recommends including, as soon as practicable, the criteria to determine when the application shall be dismantled, and which entity shall be responsible and accountable for making that determination.
The Italian Way: Immuni
Do digital rights exist?
The ... right to Internet Access?
Is the right to Internet Access an autonomous right?
(As a constitutional rank it's very difficult to restrict, while being a primary law, gives less guarantees, because another law could reduce its validity).
(There is a tendency of connecting the Right to Internet Access to the freedom of expression, and the step forward that the European framework has made is not only to consider the means to access internet, but also the quality to enjoy the Internet (such as speed of the connection)).
Problems Connected to Internet Access
Does the Internet need a Bill of Rights? Internet Governance Forum (IGF) purpose is to support the United Nations Secretary-General in carrying out the mandate from the World Summit on the Information Society (WSIS) with regard to convening a new forum for multi-stakeholder policy dialogue. (http://www.intgovforum.org)
A Way to Reconcile Natural Freedoms and Regulatory Needs?
An Internet Bill of Rights
UN Report - 2011
(There is a big difference between looking at the Right to Internet Access as a Human Right or as a Fundamental Right, because when dealing with it as a fundamental right, we have to take into consideration the specific constitutions of the States which will of course behave differently).
Internet Access: A Fundamental Right?
Internet and Constitutional Provisions Only few (recent) Constitutions have specific provisions concerning the Internet and/or the freedom on the Internet and/or the free access to the Web.
Estonia,
Finland
Spain
Internet access is part of the telecommunications universal service and must be provided with a broadband at a downstream of at least 1 Mbit/second. Internet access must be guaranteed regardless of the specific devices or technologies (access is not limited to fixed infrastructures). It is for the Government to establish the conditions for accessing the public network and to modify the connection speed in accordance to the technological advancements.
US Supreme Court
UK Courts
French Conseil Constitutionnel
Costa Rica's Constitutional Court
Conclusions