The shift towards platform liability: four judgments, one clear direction of travel

Partnerblog

There was a time when “we’re just the platform” was close to a legal magic word. Host the content, don’t look too closely, and Article 14 of the e-Commerce Directive (now Article 6 of the Digital Services Act) would generally shield the provider. That landscape is shifting, not because of any single piece of legislation, but because society and courts are converging on the same idea from several directions at once: if a platform shapes, structures, or profits from what its users publish, it may have to bear greater responsibility.

Four recent judgments, read together, tell a coherent story about where EU platform liability is heading. They come from different corners of the law – trade mark law, data protection, and the e-Commerce Directive’s own hosting exemption – yet the underlying logic is the same.

What follows goes through each in turn chronologically, and what it means for anyone advising platforms, or building one.

Amazon v Louboutin (C-148/21 & C-184/21): when “just a marketplace” stops being a defence

A turning point came with the CJEU’s judgment of 22 December 2022 in the joined Louboutin cases against Amazon. Christian Louboutin’s red sole is a registered EU trade mark, and third-party sellers were advertising red-soled shoes on Amazon’s marketplace without its consent. The question was whether Amazon itself “uses” the infringing sign within the meaning of art. 9(2)(a) of the European Union Trade Mark Regulation, or is merely providing the technical infrastructure for someone else’s use, as the Court had previously found for eBay-style marketplaces in L’Oréal and Coty Germany.

The Court reframed the test. It did not ask whether Amazon controlled the advertisement, but whether a well-informed, reasonably observant user would perceive a link between Amazon’s own services and the trade mark at issue, in particular whether that user might believe Amazon itself was marketing the goods. The Court pointed to the very features that make Amazon’s hybrid model commercially effective: uniform presentation of its own and third-party listings, its logo on all of them, and an integrated bundle of services (storage, shipping, support) that sellers plug into. Those same features can tip Amazon into being a “user” of the mark, potentially liable alongside the seller.

This matters because trade mark liability no longer hinges on who is formally behind the listing. A platform that presents its own and its third-party sellers’ products under one look and one logo risks being treated as if it made the infringing use itself.

Russmedia (C-492/23): the GDPR does not care about your hosting exemption

If Louboutin softened the marketplace shield from the trade mark side, the CJEU’s judgment of 2 December 2025 in Russmedia narrows it considerably from the data protection side.

An anonymous third party posted a fake, harmful advertisement on a Romanian classifieds site using a woman’s photographs and phone number without consent. It was removed within an hour of a complaint, but had already been copied elsewhere, so the damage was, in practice, permanent.

Russmedia’s defence was the classic one: it is a hosting provider, it did not create the content, and Article 14 protects it as long as it acted expeditiously once notified, which it did. The Court’s answer is arguably the most important line in this quartet: the e-Commerce Directive (now DSA) liability shield simply does not apply to GDPR obligations. Article 1(5)(b) of that directive carves out matters covered by data protection law, and Article 2(4) GDPR confirms the two regimes are not meant to interfere with each other.

That means a marketplace operator that qualifies as a controller of personal data in user advertisements cannot hide behind hosting-provider status when the GDPR is the applicable regime. Russmedia was treated as a joint controller because it set the parameters for how advertisements were shown and reserved broad rights in its terms and conditions to reuse and redistribute posted content for its own commercial purposes.

The Court did not stop there but also imposed stringent preventive obligations on platform operators (acting as controllers) under Articles 24 and 25 GDPR with regard to the publication of sensitive data.

That is a significant development for platforms built on free, largely unmoderated posting, since it means actually screening sensitive content before it goes live – exactly what the e-Commerce Directive and DSA’s “no monitoring” rule was meant to spare them from. The GDPR gives them no way around that: as a joint controller alongside the user, a platform must itself be able to demonstrate compliance, or it can be held liable.

Coyote (C-190/24): how much your algorithm decides can cost you the liability shield

The third case, the CJEU’s judgment of 16 June 2026 concerning Coyote System, turns on Article 14 of the e-Commerce Directive itself.

Coyote runs a driving-assistance and geolocation app through which users report roadside police checks in real time. France wanted to prohibit the rebroadcasting of that information, since it can help drivers evade checks, and the question was whether Coyote could still count as a neutral “host” of that user-submitted information at all.

The Court’s answer turns the hosting exemption on how the platform’s algorithm actually behaves. Article 14 only protects a provider whose role is neutral: merely technical, automatic, and passive, with no knowledge of or control over the information it stores. Where an operator uses an algorithm to determine, in its own interest, the conditions, manner, and order in which information is broadcast, it is exercising control over that content and may no longer be able to rely on the exemption, regardless of whether it ever looked at the content itself.

The lesson: the hosting exemption is not a status a platform simply has by virtue of being a marketplace or an app for user-generated content. A recommendation engine, a ranking system, or any filter that decides what surfaces, when, and to whom may be enough to call into question whether the platform can still rely on Article 14 protection.

AGCOM v Google (C-421/24): reviewing content for a revenue deal costs you neutrality

The newest addition to this line, the Court’s judgment of 16 July 2026 in AGCOM v Google, sharpens the Article 14 test with a concrete fact pattern.

Italy fined Google for allowing YouTube channels to advertise gambling in breach of Italian law and ordered hundreds of videos removed. Google argued it was a neutral host of the videos within the meaning of Article 14 of the e-Commerce Directive, but lost. The channels had entered YouTube’s Partner Programme, a commercial partnership sharing advertising revenue, which required Google to review each channel’s main theme, its most-viewed or newest videos, and their metadata before granting access. That review, the Court held, gave Google specific knowledge of the essential content of those channels, even though it never watched every video. A platform that reviews content to decide whether to enter a revenue-sharing deal is no longer a passive, neutral intermediary, and it loses Article 14 protection for that content.

The lesson here is distinct from Coyote: algorithms are not the only thing that can cost a platform its liability shield, ordinary commercial due diligence can too. Vetting a user’s content before offering a monetisation deal is a business decision, but it also amounts, in the Court’s eyes, to knowledge that forecloses neutrality.

Four judgments, one direction

None of these judgments cites the others, yet in each case the deciding factor is something the platform itself designed or decided to do: the parameters shaping how listings are displayed, the terms and conditions reserving rights over user content, the algorithm deciding what is broadcast and to whom, or the decision to vet content before monetising it. These are choices about the platform’s own architecture and business model, not about any individual user’s post, and that is precisely why they can tip the balance towards liability.

These judicial developments do not exist in isolation. They arguably reflect, and are in part informed by, a broader conversation taking place across regulators, policymakers, and society at large about the role digital platforms play in everyday life and the responsibilities that may come with that role. The judgments can be seen as one expression of that evolving dialogue, rather than its sole driver.

Platforms are no longer assessed solely on whether they authored the content in question. Increasingly, they are judged on how their own design and commercial choices shape what happens, and on whether they could realistically have prevented the harm rather than merely reacting once it occurred.

For legal teams advising platforms, or building them, the practical takeaway is consistent across all four grounds: the traditional distinction between “hosting provider, therefore protected” and “content provider, therefore liable” is giving way to a more nuanced inquiry into the platform’s own design choices, algorithms, contractual terms, and commercial practices, and what they reveal about its integration, perception, and control. The practical question for any platform is no longer “are we a host”, but “what does our design, and our business model, decide for our users, and could we reasonably have done more to prevent the harm”.

Author

Jill Van Overbeke

Delen