Law / European Union

Terrorist Content Online Regulation, Articles 5, 6, 7 and 10 (Specific measures, preservation of content, transparency and complaints)

Regulation (EU) 2021/784, Arts. 5-7, 10

In force since .

A specific illegal content rule binding private bodies.

Private right of action
No
Obligation class
Governance, Retention, Disclosure, Reporting

As of .

What it requires

  • If you are a hosting service provider that the competent authority of the Member State of your main establishment (or where your legal representative resides or is established) has found, by a decision notified to you and based on objective factors such as two or more final removal orders in the previous 12 months, to be exposed to terrorist content, include provisions in your terms and conditions, where applicable, and apply them to address the misuse of your services for the dissemination to the public of terrorist content, in a diligent, proportionate and non-discriminatory manner (Articles 5(1) and 5(4)).
  • Take specific measures to protect your services against the dissemination to the public of terrorist content; the choice of measures stays with you, and they must be effective in mitigating your exposure, targeted and proportionate, applied with full account of your users' rights and legitimate interests, and applied in a diligent and non-discriminatory manner (Articles 5(2) and 5(3)).
  • Report to the competent authority on the specific measures you have taken and intend to take, within three months of receiving the decision and annually thereafter, until the authority decides on your request that you are no longer exposed to terrorist content (Articles 5(5) and 5(7)).
  • If the competent authority finds that your specific measures do not comply with Article 5(2) and (3), take the necessary measures its decision requires; you may choose the type of specific measures (Article 5(6)).
  • If you are a hosting service provider, preserve terrorist content you have removed, or access to which you have disabled, as a result of a removal order or of specific measures, together with the related data removed as a consequence, where they are necessary for administrative or judicial review proceedings, for complaint-handling under Article 10, or for the prevention, detection, investigation and prosecution of terrorist offences; keep them for six months from the removal or disabling, and for a further specified period on the request of the competent authority or a court only if and for as long as necessary for ongoing administrative or judicial review proceedings (Articles 6(1) and 6(2)).
  • Keep the preserved terrorist content and related data under appropriate technical and organizational safeguards that ensure they are accessed and processed only for those purposes and that a high level of security of the personal data concerned is maintained, and review and update the safeguards where necessary (Article 6(3)).
  • Set out clearly in your terms and conditions your policy for addressing the dissemination of terrorist content, including, where appropriate, a meaningful explanation of the functioning of specific measures and, where applicable, the use of automated tools (Article 7(1)).
  • If you took action to address the dissemination of terrorist content, or were required to take action under the Regulation, in a calendar year, make a transparency report on those actions publicly available before 1 March of the following year, covering at least your measures to identify and remove or disable terrorist content and to address its reappearance, the number of items removed or disabled following removal orders or specific measures, the number and outcome of complaints and of review proceedings you brought, and the cases in which you were required to reinstate, or reinstated, content or access (Article 7(2) and (3)).
  • Establish an effective and accessible mechanism that allows content providers whose content you removed, or access to which you disabled, as a result of specific measures under Article 5 to submit a complaint requesting the reinstatement of the content or of access (Article 10(1)).
  • Examine every complaint expeditiously and reinstate the content or access without undue delay where the removal or disabling was unjustified; inform the complainant of the outcome within two weeks of receipt and give the reasons where you reject the complaint (Article 10(2)).

Who enforces it

Enforcement body

The competent authorities each Member State designates to oversee the implementation of specific measures under Article 5 and to impose penalties under Article 18 (Article 12(1), points (c) and (d)).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 1(2) applies the Regulation to hosting service providers offering services in the Union, irrespective of their place of main establishment, insofar as they disseminate information to the public. Article 2(1) defines a hosting service provider as a provider of services, as defined in point (b) of Article 1 of Directive (EU) 2015/1535, consisting of the storage of information provided by and at the request of a content provider.

Article 5(4) provides that a hosting service provider is exposed to terrorist content where the competent authority of the Member State of its main establishment, or where its legal representative resides or is established, has taken a decision, on the basis of objective factors such as the provider having received two or more final removal orders in the previous 12 months, finding that it is exposed to terrorist content, and has notified the decision to the provider.

Article 5(1) requires a hosting service provider exposed to terrorist content to include in its terms and conditions, where applicable, and apply provisions to address the misuse of its services for the dissemination to the public of terrorist content, in a diligent, proportionate and non-discriminatory manner.

Article 5(2) requires such a provider to take specific measures to protect its services against the dissemination to the public of terrorist content, and leaves the choice of specific measures with the provider. Article 5(3) requires specific measures to be effective in mitigating the level of exposure, targeted and proportionate, applied in a manner that takes full account of the rights and legitimate interest of the users, and applied in a diligent and non-discriminatory manner.

Article 5(5) requires such a provider to report to the competent authority on the specific measures it has taken and intends to take within three months of receipt of the decision and on an annual basis thereafter. That reporting obligation ceases once the competent authority has decided, upon the provider's request, that the provider is no longer exposed to terrorist content.

Article 5(6) provides that, where the competent authority considers, based on the reports and, where relevant, any other objective factors, that the specific measures taken do not comply with Article 5(2) and (3), it addresses a decision to the provider requiring it to take the necessary measures, and the provider may choose the type of specific measures to take.

Article 5(8) provides that a requirement to take specific measures entails neither a general obligation to monitor the information which hosting service providers transmit or store nor a general obligation actively to seek facts or circumstances indicating illegal activity, and does not include an obligation to use automated tools.

Article 6(1) requires hosting service providers to preserve terrorist content which has been removed or access to which has been disabled as a result of a removal order or of specific measures, with any related data removed as a consequence, where necessary for administrative or judicial review proceedings, for complaint-handling under Article 10, or for the prevention, detection, investigation and prosecution of terrorist offences.

Article 6(2) requires the content and related data to be preserved for six months from the removal or disabling, and for a further specified period on request of the competent authority or court only if and for as long as necessary for ongoing administrative or judicial review proceedings.

Article 6(3) requires hosting service providers to ensure that the preserved content and data are subject to appropriate technical and organizational safeguards, so that they are accessed and processed only for the purposes of Article 6(1) and a high level of security of the personal data concerned is ensured.

Article 7(1) requires hosting service providers to set out clearly in their terms and conditions their policy for addressing the dissemination of terrorist content, including, where appropriate, a meaningful explanation of the functioning of specific measures and, where applicable, the use of automated tools.

Article 7(2) requires a hosting service provider that has taken action to address the dissemination of terrorist content, or has been required to take action under the Regulation, in a given calendar year to make publicly available a transparency report on those actions for that year, published before 1 March of the following year.

Article 7(3) requires the transparency report to include at least the provider's measures to identify and remove or disable terrorist content and to address its reappearance, the number of items removed or disabled following removal orders or specific measures, the number and outcome of complaints and of review proceedings, and the cases in which content or access was reinstated.

Article 10(1) requires each hosting service provider to establish an effective and accessible mechanism allowing content providers whose content has been removed or access to which has been disabled as a result of specific measures under Article 5 to submit a complaint requesting reinstatement.

Article 10(2) requires each hosting service provider to examine all complaints expeditiously, reinstate the content or access without undue delay where the removal or disabling was unjustified, inform the complainant of the outcome within two weeks of receipt, and provide the reasons where the complaint is rejected.

Article 18(1) requires Member States to lay down the rules on penalties for infringements of the Regulation by hosting service providers, limits them to infringements of listed provisions that include Article 5(1), (2), (3), (5) and (6) and Articles 6, 7 and 10, and requires them to be effective, proportionate and dissuasive. Article 24 provides that the Regulation applies from and is binding in its entirety and directly applicable in all Member States.

When LexLint raises it

When your app profile says your app operates a social platform.

Back to the example  ·  Lint your app