Second transit carrier live in Chișinău — 20 Gbps of blended capacity. 20 Gbps blended uplink now live Why Moldova

Legal Reference

DMCA, DSA and the e-Commerce Directive, compared

Three instruments, three different triggers, and which of them can reach a host outside their territory. Written for someone who has received a notice and wants to know what it obliges.

17 min read Published 11 June 2026 Checked 1 month ago

These three get used interchangeably in conversation and they are not interchangeable at all. They have different triggers, different addressees, and — the part that matters most — different territorial scope. This is a reference rather than an argument; it is not legal advice, and where a real dispute is running you want a lawyer in the relevant country rather than a web page.

The three, side by side

Comparison of the three instruments
InstrumentOriginBinds a host abroadWhat it actually does
DMCA — 17 U.S.C. § 512United States No Creates a safe harbour, conditioned on running notice-and-takedown. Domestic law, not a treaty, with no extraterritorial removal mechanism.
e-Commerce Directive 2000/31/ECEuropean Union No Conditions liability protection on acting expeditiously once aware. Applies to information-society services established in a Member State.
Digital Services Act (EU) 2022/2065European Union Sometimes Adds notice mechanisms, timelines and trusted flaggers. Reaches intermediaries offering services in the Union, which is a broader test than establishment.

DMCA — 17 U.S.C. § 512

The most misunderstood of the three, largely because its name gets used as a verb. Section 512 does not order anyone to remove anything. It offers providers a safe harbour from monetary liability for their users’ infringements, and it makes that safe harbour conditional on several things — including designating an agent, responding expeditiously to properly formed notices, and terminating repeat infringers in appropriate circumstances.

The practical consequence is an incentive rather than an order. An American provider that ignores a notice does not commit an offence by ignoring it; it loses a defence it would very much like to keep. Because that defence is worth more than any single customer, the rational move is always to remove first. That is why removal feels automatic there: the system is designed to make it the cheapest option.

What a § 512 notice is: a request that triggers a contractual and statutory reflex inside a provider that has chosen to claim the safe harbour.

What it is not: a court order, a finding of infringement, or an instrument with any force against a provider that never claimed the safe harbour in the first place.

Counter-notice under § 512(g) exists to restore material that was removed. Where nothing was removed, there is nothing to counter — which is why hosts outside the United States generally have no counter-notice procedure. It would be a procedure with no input.

The e-Commerce Directive

Directive 2000/31/EC gives information-society services a conditional liability shield: a host is not liable for stored information provided it has no actual knowledge of illegality and, upon obtaining knowledge, acts expeditiously to remove or disable access.

Two words carry the whole thing. Established defines who the Directive applies to — a provider with a fixed establishment in a Member State, pursuing an economic activity there. And expeditiously is deliberately undefined, which in practice means “fast enough that a court will not second-guess you”, which in practice means very fast.

There is no notice format prescribed by the Directive, which surprises people. Knowledge can arrive by any means. That is precisely why providers inside the Union treat almost any credible-looking message as knowledge: once you are aware, the clock is running, and the safest reading of an undefined deadline is “now”.

The Digital Services Act

Regulation (EU) 2022/2065 does not replace the liability regime; it builds process on top of it. For hosting providers it introduces a mandatory notice-and-action mechanism, a duty to give reasons for decisions, priority handling for trusted flaggers, and — for very large platforms — a set of obligations that do not apply to ordinary hosts at all.

The scope test is the important change. The DSA reaches intermediary services offered to recipients in the Union, regardless of where the provider is established, and requires providers outside the Union that fall within that test to designate a legal representative inside it. That is a broader hook than the Directive’s establishment test.

Whether it catches a particular host turns on whether it is offering services in the Union, which in the Regulation’s own terms involves a substantial connection to the Union — such things as an establishment, a significant number of recipients there, or targeting activities directed at one or more Member States. A host with no establishment, no targeting and no Union-specific offering is outside it; a host advertising in Member State languages and pricing in euro is having a different conversation.

Which of them reaches a host abroad

Reducing it to the practical answer:

  • DMCA: no mechanism at all against a provider outside United States jurisdiction. A notice sent to one is correspondence. It may be perfectly polite and perfectly well-founded correspondence, and it remains correspondence.
  • e-Commerce Directive: the obligation depends on establishment in a Member State. A provider without one is outside the regime — it is also outside its protection, which matters only if it wanted it.
  • DSA: depends on whether the provider offers services in the Union. This is the one worth actually checking, because the answer is not automatically no.

What does reach a host abroad, in every case, is an order from a court in its own jurisdiction. A foreign judgment is not self-executing anywhere: it must be recognised locally, which normally means mutual legal assistance and a local court. Public, adversarial, slow — and, for most complainants, not worth it. That asymmetry is the entire product.

If you have just received a notice

  1. Work out who it was actually sent to. If it came via your host, your host’s jurisdiction decides what happens next, not yours and not the sender’s.
  2. Check whether it is an order or a request. Almost all of them are requests. An order names a court, a case, and a judge.
  3. Do not reply admitting anything. A reply is not required by any of the three instruments where the recipient is outside their scope, and an admission is durable in a way the notice is not.
  4. Keep it. Volume and pattern matter later, particularly if the same sender is working through a list rather than reading your site.
  5. Get local advice if a court is named. That is the point at which a web page stops being useful and a lawyer in the relevant country starts.

Our own handling is written down rather than described in adjectives: a notice is logged, timestamped, counted and forwarded to the customer verbatim within 24 hours, and nothing about the service changes. The DMCA policy sets out the procedure from both sides, and the transparency report publishes how many arrive each quarter alongside how many removals they produced.

Written by the engineers who run the platform, and re-read 1 month ago. If something here is wrong or has gone out of date, say so from the panel — that is where about half of these came from.

Language

Read this site in your language

Available in 28 languages today. The rest are being translated.