Civil Law And Data Hosting Service Liability Claims In Europe .
Civil Law and Data Hosting Service Liability Claims in Europe
1. Introduction
Data hosting service liability concerns the civil and regulatory responsibility of a provider that stores data, files, applications, websites, databases, images, videos, communications or other information on behalf of customers or users.
Examples include:
- cloud-storage providers;
- web-hosting companies;
- file-hosting platforms;
- video-sharing platforms;
- online marketplaces storing seller information;
- social-media platforms;
- enterprise cloud providers;
- database-hosting providers;
- application-hosting providers.
The central legal question is:
When should a hosting provider be responsible for unlawful, harmful, inaccurate, infringing or dangerous information stored on its infrastructure by another person?
European law has historically attempted to balance two competing interests:
Protection of victims
against
Protection of neutral intermediaries from unlimited liability.
The older framework was principally Article 14 of the E-Commerce Directive 2000/31/EC. Since 17 February 2024, the Digital Services Act (DSA), Regulation (EU) 2022/2065, has become the central EU framework for intermediary services, including hosting services. Article 6 DSA contains the hosting liability exemption, while also preserving the possibility of judicial or administrative orders to terminate or prevent infringements.
2. Meaning of a Data Hosting Service
A hosting service generally involves:
Storage of information provided by a recipient of the service.
Examples:
Cloud storage
A customer uploads files to a cloud platform.
Website hosting
A customer stores a website and associated databases on a hosting provider's servers.
File hosting
Users upload documents, photographs, videos or other files.
Platform hosting
A platform stores user-generated content.
Application hosting
A provider stores and runs software and associated customer data.
Database hosting
A provider maintains databases containing customer information.
3. Basic Liability Model
The basic relationship can be represented as:
User/customer
↓
uploads or provides information
↓
Hosting provider
↓
stores information
↓
third party suffers harm
↓
Potential civil claim
The important question is whether the provider merely supplied storage infrastructure or whether its conduct went beyond neutral hosting.
4. European Legal Framework
A. Digital Services Act
The principal modern EU instrument is:
Regulation (EU) 2022/2065 — Digital Services Act (DSA).
Article 6 provides a liability exemption for hosting services where the provider does not have actual knowledge of illegal activity or illegal content and, concerning claims for damages, is not aware of facts or circumstances from which the illegality is apparent; once the provider obtains the required knowledge or awareness, it must act expeditiously to remove or disable access.
This creates a fundamental structure:
No relevant knowledge → safe harbour
Relevant knowledge → prompt action required
5. Important Point: Hosting Does Not Mean Automatic Immunity
A provider cannot simply say:
“We are a hosting company, therefore we can never be liable.”
The legal analysis asks:
- Is the service actually a hosting service?
- Is the provider covered by the relevant liability exemption?
- Did the provider have actual knowledge?
- Was there sufficient information to establish apparent illegality?
- Did the provider respond expeditiously?
- Did the provider itself play an active role?
- Is a separate cause of action available?
- Is the claim about third-party content or the provider's own conduct?
The CJEU has repeatedly emphasised that intermediary liability protection depends upon the nature of the provider's activity and the statutory conditions.
6. Historical E-Commerce Directive
Before the DSA, Article 14 of Directive 2000/31/EC provided the principal EU hosting safe harbour.
The provider generally avoided liability where:
- it lacked actual knowledge of illegal activity/information; or
- it lacked awareness of facts or circumstances making illegality apparent; and
- after obtaining the necessary knowledge, it acted expeditiously to remove or disable access.
The DSA has replaced the E-Commerce Directive's former intermediary liability provisions at EU level, but the extensive CJEU case law under the earlier framework remains highly important for understanding concepts such as hosting, knowledge, active role and injunctions.
7. Types of Data Hosting Liability
7.1 Copyright infringement
A user may upload:
- films;
- music;
- books;
- photographs;
- software;
- databases.
The copyright owner may seek relief against the hosting provider.
7.2 Defamation
A user might upload defamatory information to a hosted website.
The victim may seek:
- removal;
- injunction;
- damages;
- identification of the uploader where legally available.
7.3 Privacy violations
Hosted data may contain:
- private photographs;
- personal information;
- medical information;
- financial information;
- confidential correspondence.
7.4 Data-protection violations
A hosting provider may become involved in disputes concerning:
- unlawful processing;
- inadequate security;
- unauthorised disclosure;
- data breaches;
- retention;
- access rights.
7.5 Trade-secret violations
A hosted file may contain:
- source code;
- manufacturing plans;
- business strategies;
- customer databases;
- confidential contracts.
7.6 Illegal goods or services
A platform may store listings concerning unlawful products or services.
7.7 Cybersecurity-related harm
A compromised hosting account could facilitate:
- malware distribution;
- ransomware;
- phishing;
- credential theft;
- botnet activity.
The provider's civil liability depends upon the particular contractual, statutory and tort/delict duties involved.
8. Hosting Provider vs Active Service Provider
This is one of the most important distinctions.
Neutral provider
The provider:
- stores information;
- operates servers;
- supplies technical infrastructure;
- performs automated processing;
- does not determine the substance of the information.
Active provider
The provider may:
- select content;
- modify content;
- optimise content;
- promote particular content;
- control information;
- exercise editorial influence;
- acquire knowledge of particular illegal content.
The CJEU's earlier case law explains that intermediary exemptions were directed at providers whose activity was essentially technical, automatic and passive rather than providers exercising knowledge or control over the information.
9. Actual Knowledge
Actual knowledge is crucial.
Suppose a hosting company receives a sufficiently specific notice:
“This particular file at this particular address contains an unauthorised copy of my copyrighted work.”
The provider may then need to examine the notification and take appropriate action under the applicable legal regime.
A vague statement such as:
“Your website contains illegal material”
may present a different legal problem.
The adequacy of notice is therefore important.
10. Notice-and-Action
A simplified model is:
Illegal content
↓
Specific notification
↓
Provider obtains relevant knowledge
↓
Provider investigates/assesses
↓
Removal or disabling of access
↓
Potential restoration where justified
The DSA retains the fundamental requirement that a hosting provider act expeditiously after obtaining the relevant knowledge or awareness.
11. Civil Damages
A claimant seeking damages may have to establish:
1. Duty
The provider owed a legally recognised duty.
2. Breach
The provider failed to comply with that duty.
3. Causation
The breach caused the loss.
4. Damage
The claimant suffered legally recoverable harm.
5. Absence of applicable immunity
The provider cannot successfully rely upon the applicable hosting exemption.
12. Contractual Liability
A customer may sue the hosting provider under a service agreement.
Typical contractual obligations include:
- server availability;
- data security;
- backup;
- confidentiality;
- disaster recovery;
- service levels;
- data integrity;
- restoration;
- cybersecurity;
- deletion;
- migration.
For example:
A company stores its business database with a cloud-hosting provider. The provider fails to maintain agreed backups, and a server failure permanently destroys the customer's data.
This is fundamentally different from a claim concerning unlawful third-party content.
The provider may therefore have contractual liability even where intermediary safe-harbour rules concerning third-party content are irrelevant.
13. Tort / Delict Liability
National civil laws may recognise liability for:
- negligence;
- unlawful interference;
- breach of statutory duties;
- culpa;
- defective security;
- privacy violations;
- property damage;
- economic loss.
The exact requirements differ among European jurisdictions.
14. Data Loss Claims
A hosting provider can face a claim where customer data is:
- accidentally deleted;
- corrupted;
- overwritten;
- encrypted through ransomware;
- made unavailable;
- improperly migrated.
Potential questions include:
- Was backup contractually required?
- Was redundancy promised?
- Were recovery procedures adequate?
- Did the customer follow security instructions?
- Was the incident foreseeable?
- Did force majeure apply?
- What was the customer's actual financial loss?
15. Cybersecurity Hosting Claims
Suppose:
Company A → stores database with Cloud Provider B
A hacker compromises the provider's infrastructure.
The customer's database is stolen.
Possible legal claims concern:
- security obligations;
- contractual warranties;
- negligence;
- GDPR;
- confidentiality;
- incident response;
- allocation of cyber risk.
The existence of a cyberattack does not automatically establish provider liability.
The claimant may have to establish that the provider's security failure contributed causally to the loss.
16. Important Case Law
The following cases are particularly useful for European hosting-liability analysis. The first group establishes the EU intermediary/hosting principles; the later cases demonstrate their application to injunctions, copyright and platform liability.
Case 1 — Google France and Google
Joined Cases C-236/08 to C-238/08, Google France and Google Inc. v Louis Vuitton Malletier SA and Others
CJEU, 23 March 2010
This is one of the foundational EU intermediary-liability cases.
The litigation concerned Google's AdWords service and trademark-related advertisements.
The CJEU considered the conditions under which an information-society service provider could benefit from the hosting safe harbour.
Principle
The provider's activity must be sufficiently neutral.
Where the provider plays an active role giving it knowledge or control over the stored data, the hosting exemption may not apply in the same manner.
Importance
The case establishes an important distinction between:
technical hosting
and
active involvement in stored information.
That distinction remains fundamental to modern data-hosting liability analysis.
Case 2 — L'Oréal v eBay
Case C-324/09, L'Oréal SA and Others v eBay International AG and Others
CJEU, 12 July 2011
Facts
L'Oréal alleged trademark infringement involving goods sold through eBay.
The CJEU considered:
- intermediary liability;
- hosting;
- trademark infringement;
- injunctions against intermediaries.
Principle
An intermediary that plays an active role in relation to information may fall outside the hosting exemption.
The Court also considered circumstances in which courts can grant injunctions against intermediaries.
Importance for data hosting
This case demonstrates that storage alone does not settle the liability question.
The court must examine what the provider actually does.
It is therefore highly relevant to:
- cloud platforms;
- online marketplaces;
- managed hosting;
- content platforms;
- database-hosting services.
Case 3 — Scarlet Extended v SABAM
Case C-70/10, Scarlet Extended SA v SABAM
CJEU, 24 November 2011
This case concerned an injunction requiring an internet service provider to install a system for filtering electronic communications to prevent copyright infringement.
The CJEU rejected the requirement for a general and permanent filtering system of the type proposed because it conflicted with EU law and fundamental rights.
Principle
A hosting/intermediary provider cannot ordinarily be subjected to an unlimited obligation to monitor all communications in advance.
Importance
This is extremely important for data-hosting providers.
It establishes a distinction between:
specific removal obligations
and
general monitoring obligations.
Case 4 — SABAM v Netlog
Case C-360/10, Belgische Vereniging van Auteurs, Componisten en Uitgevers CVBA (SABAM) v Netlog NV
CJEU, 16 February 2012
Facts
Netlog operated an online social-networking platform.
SABAM sought an injunction requiring the platform to prevent copyright infringement by its users.
Decision
The CJEU rejected the imposition of a general filtering obligation comparable to the one considered in Scarlet Extended.
Principle
A hosting platform cannot generally be forced to install a broad preventive monitoring system covering all users and all content.
Relevance
The case remains important for:
- cloud platforms;
- social networks;
- file-hosting systems;
- user-generated-content platforms.
It illustrates the importance of balancing intellectual-property enforcement with:
- privacy;
- freedom of expression;
- freedom to conduct a business.
Case 5 — Glawischnig-Piesczek v Facebook Ireland
Case C-18/18, Eva Glawischnig-Piesczek v Facebook Ireland Limited
CJEU, 3 October 2019
This is a major case on removal and injunctions against hosting providers.
The dispute arose after defamatory material was posted on Facebook.
The CJEU considered whether an Austrian court could require Facebook to remove unlawful content and prevent equivalent content from being reposted.
Principle
The absence of a general monitoring obligation does not prevent courts from imposing specific and sufficiently defined injunctions.
The Court recognised that a hosting provider can, in appropriate circumstances, be required to remove:
- the specific unlawful information; and
- information that is equivalent to it.
The judgment expressly addressed Articles 14, 15 and 18 of the E-Commerce Directive.
Importance
This case demonstrates the important boundary:
No general surveillance duty
does not mean
no removal duty after unlawful content has been identified.
Case 6 — YouTube and Cyando
Joined Cases C-682/18 and C-683/18, Frank Peterson v Google LLC, YouTube LLC and Others; Elsevier Inc. v Cyando AG
CJEU, 22 June 2021
This is one of the most important modern cases involving video-sharing and file-hosting platforms.
The Court examined:
- copyright infringement;
- hosting;
- platform liability;
- communication to the public;
- Article 14 safe harbour;
- injunctions.
The CJEU held that the operators of such platforms do not, merely by making their platforms available, necessarily carry out a copyright-relevant act of communication to the public for every unlawful upload by users. The hosting exemption and the conditions surrounding it remained important.
Importance
The case is highly relevant to:
- file-hosting platforms;
- cloud storage;
- video hosting;
- user-generated content;
- copyright disputes.
It also emphasised the significance of whether the provider had specific knowledge of infringements and whether it acted after notification.
Case 7 — WebGroup Czech Republic and Others
Joined Cases C-188/24 and C-190/24
CJEU, 16 June 2026
This is particularly important because it reflects the current post-DSA legal landscape.
The CJEU considered the concept of hosting and intermediary liability in the context of services involving storage and dissemination of information.
The Court reiterated that merely storing information is not enough, by itself, to establish that every such service qualifies for the hosting exemption. The relevant intermediary character and statutory conditions must be examined.
Importance
This is useful for modern data-hosting litigation because it demonstrates that:
“Our servers store data” is not, by itself, a complete legal defence.
The nature and functioning of the service must be examined.
Case 8 — AGCOM (Online Gambling)
Case C-421/24, AGCOM (Online gambling)
CJEU, 16 July 2026
The Court addressed liability of Google in relation to YouTube videos promoting online gambling and considered the hosting-service exemption.
The case involved an Italian regulatory decision imposing a fine and removal obligations concerning videos uploaded by a content creator who had a commercial relationship with Google. The Court examined the relevance of Google's involvement with the content and the hosting liability framework.
Importance
This is particularly useful for modern platform cases because it shows that:
- commercial relationships matter;
- content-related involvement matters;
- hosting cannot be analysed purely by looking at the technical fact of storage.
It is therefore a useful current authority when analysing whether a sophisticated platform remains within a hosting safe harbour.
17. Case-Law Summary Table
| Case | Court | Main issue | Importance |
|---|---|---|---|
| Google France v Louis Vuitton C-236/08–C-238/08 | CJEU | Hosting and active role | Neutrality vs active involvement |
| L'Oréal v eBay C-324/09 | CJEU | Marketplace hosting and injunctions | Active role and intermediary responsibility |
| Scarlet Extended v SABAM C-70/10 | CJEU | General filtering | No general monitoring obligation |
| SABAM v Netlog C-360/10 | CJEU | Social-network filtering | Protection against general surveillance |
| Glawischnig-Piesczek v Facebook C-18/18 | CJEU | Defamatory content and injunctions | Specific/equivalent-content removal |
| YouTube and Cyando C-682/18 & C-683/18 | CJEU | Video/file hosting | Platform and copyright liability |
| WebGroup Czech Republic C-188/24 & C-190/24 | CJEU | Modern hosting/intermediary status | Current interpretation |
| AGCOM (Online gambling) C-421/24 | CJEU | YouTube hosting liability | Current post-DSA relevance |
18. Data Hosting and Copyright
Copyright is one of the most developed areas of hosting litigation.
A user uploads:
“Movie_X.mp4”
The copyright owner alleges infringement.
Three questions arise:
Question 1
Did the user infringe copyright?
Question 2
Is the hosting provider itself legally responsible?
Question 3
What action can a court require from the provider?
Cases such as L'Oréal, Scarlet Extended, Netlog, Glawischnig-Piesczek and YouTube/Cyando help answer these questions.
19. Defamation and Hosting
Suppose a user uploads:
“Company X commits fraud.”
The company demands removal.
The hosting provider must consider:
- whether the content is unlawful;
- whether the notification provides sufficient information;
- whether a court order exists;
- whether the provider has relevant knowledge;
- whether removal is required;
- whether freedom of expression is implicated.
Glawischnig-Piesczek is especially important because it demonstrates that a court may require specific removal and prevention of equivalent unlawful material without imposing an unlimited general monitoring obligation.
20. Data Protection and Hosting
Hosting providers may process enormous amounts of personal data.
Possible liability issues include:
- unauthorised disclosure;
- inadequate technical safeguards;
- unlawful access;
- retention;
- deletion;
- data-subject rights;
- processor/controller allocation;
- cross-border transfers.
A hosting provider can therefore face two different legal dimensions:
Platform/intermediary liability
Liability for information supplied by users.
Data-protection liability
Liability arising from the provider's own processing of personal data.
These should not be automatically merged.
21. Cybersecurity Liability
Consider:
A cloud provider promises industry-standard security.
A ransomware attack compromises the provider's infrastructure.
The customer's confidential database is encrypted and unavailable for 15 days.
The customer claims:
- breach of contract;
- negligence;
- failure to maintain reasonable security;
- business interruption losses;
- restoration expenses.
The provider may defend itself by arguing:
- security complied with contractual standards;
- attack was sophisticated;
- customer security controls were defective;
- loss was too remote;
- contractual liability limits apply;
- force majeure;
- causation is not established.
22. Data Integrity
Hosting liability can also arise where data is altered rather than merely disclosed.
Examples:
- incorrect database migration;
- corrupted records;
- failed synchronisation;
- unauthorised modification;
- software incompatibility;
- failed backup restoration.
The central question becomes:
Did the provider have a legal obligation to preserve the integrity and availability of the data?
23. Service-Level Agreements
Large cloud-hosting agreements often contain:
- uptime guarantees;
- backup obligations;
- disaster recovery;
- recovery-point objectives;
- recovery-time objectives;
- cybersecurity obligations;
- incident notification;
- service credits;
- liability caps.
A civil claim may therefore be determined primarily by the contract, rather than by intermediary safe-harbour law.
This distinction is essential.
24. Liability for Customer Data vs Third-Party Data
Situation A — Customer's own data
A company pays for hosting.
The provider loses the company's database.
This is principally a:
contractual/service-liability dispute.
Situation B — Third-party unlawful content
A user uploads defamatory or infringing material.
This is principally an:
intermediary/hosting-liability dispute.
Situation C — Provider's own conduct
The provider actively modifies, promotes or controls information.
This may weaken or remove reliance on hosting protection.
25. Notice Requirements
A good notice should ideally identify:
- exact URL;
- exact file;
- specific unlawful content;
- legal basis;
- ownership/right;
- evidence;
- contact information;
- requested remedy.
A vague notification creates greater difficulty in determining whether the provider has obtained legally relevant knowledge.
26. General Monitoring vs Specific Monitoring
This distinction is extremely important.
General monitoring
“Check every file uploaded by every customer.”
EU law has historically resisted imposing such broad obligations on intermediary providers. Scarlet Extended and Netlog are central authorities.
Specific monitoring/removal
“This particular file has been judicially determined to be unlawful. Remove it and prevent its equivalent reposting.”
This can be permissible under the principles developed in Glawischnig-Piesczek.
27. Fundamental Rights
Hosting disputes involve competing rights.
Victim
Right to:
- property;
- reputation;
- privacy;
- effective remedy.
User
Right to:
- freedom of expression;
- privacy;
- information.
Hosting provider
Right to:
- conduct a business;
- avoid disproportionate regulatory burdens.
The CJEU's intermediary cases repeatedly require these interests to be balanced.
28. Territorial Scope
A hosting provider may operate:
- servers in Germany;
- customers in France;
- headquarters in Ireland;
- users across Europe.
A court may therefore have to consider:
- jurisdiction;
- applicable law;
- territorial scope of injunctions;
- recognition and enforcement;
- GDPR territorial rules;
- DSA obligations.
Glawischnig-Piesczek is especially significant because it considered the possible personal, material and territorial scope of injunctions against hosting providers.
29. Defences Available to Hosting Providers
29.1 Hosting safe harbour
The provider may argue that it satisfies Article 6 DSA.
29.2 Lack of knowledge
The provider may argue:
“We did not know about the unlawful information.”
29.3 Prompt action
The provider may establish:
“Once we received sufficient notice, we removed or disabled access promptly.”
29.4 Neutral technical role
The provider may demonstrate that it:
- merely stored information;
- did not select it;
- did not control it;
- did not actively participate in the unlawful conduct.
29.5 Causation
The provider may argue that the claimant's loss resulted from the customer's or user's conduct rather than the hosting service.
29.6 Contractual limitations
Business-to-business agreements may contain:
- liability caps;
- exclusions;
- indemnity clauses;
- service-credit provisions.
Their enforceability depends upon applicable national law and the particular contract.
30. Remedies
Potential remedies include:
Damages
Compensation for proven loss.
Injunction
Order requiring removal or prevention of specific unlawful information.
Declaration
Court declaration concerning rights or obligations.
Restitution
Recovery of improperly retained benefits where applicable.
Specific performance
Potentially relevant to contractual hosting obligations.
Removal or disabling
Particularly relevant to unlawful third-party content.
Regulatory penalties
The DSA and national legal systems may provide regulatory consequences separate from private civil damages.
31. Hypothetical Example
Suppose Company A stores its customer database with Hosting Company B.
A hacker gains access because B failed to patch a known vulnerability.
The hacker steals:
- customer names;
- addresses;
- financial information.
Company A suffers:
- investigation expenses;
- business interruption;
- customer claims;
- reputational damage.
Company A may examine:
Contract
Did B promise a particular security standard?
Negligence
Was the vulnerability reasonably foreseeable?
Causation
Did B's failure cause the breach?
Data protection
Were statutory security requirements breached?
Damages
Which losses are legally recoverable?
This is different from a case where Company A's customer uploads unlawful information to B's servers.
32. Practical Litigation Checklist
A claimant should collect:
- Hosting agreement.
- Terms of service.
- SLA.
- Security specifications.
- Backup policy.
- Incident reports.
- Server logs.
- Access logs.
- Vulnerability reports.
- Notification records.
- Removal requests.
- Correspondence.
- Expert cybersecurity evidence.
- Evidence of financial loss.
- Evidence of causation.
33. Core Legal Test
A simplified European hosting-liability analysis is:
1. Is there hosting?
↓
2. What information was stored?
↓
3. Who supplied it?
↓
4. Is it unlawful?
↓
5. Did the provider have actual knowledge?
↓
6. Was illegality apparent from the relevant facts?
↓
7. Did the provider act expeditiously?
↓
8. Did the provider play an active role?
↓
9. Is there a separate contractual/tort/data-protection duty?
↓
10. Did the claimant suffer legally recoverable damage?
↓
11. Is causation established?
↓
12. What remedy is available?
34. Conclusion
European data-hosting liability is based on a conditional intermediary-liability system, not absolute immunity.
The basic principle is:
A hosting provider should not automatically become liable merely because unlawful information is stored on its infrastructure by a user.
At the same time:
A provider cannot necessarily rely on hosting protection where it has the legally relevant knowledge and fails to act, or where its own active involvement, contractual obligations or other legal duties create liability.
The most important authorities are Google France, L'Oréal v eBay, Scarlet Extended, SABAM v Netlog, Glawischnig-Piesczek, and YouTube/Cyando, with the 2026 WebGroup Czech Republic and AGCOM (Online gambling) judgments particularly useful for understanding the evolving modern framework. The older CJEU cases remain important, but their reasoning must now be read alongside the DSA's autonomous liability regime.
Exam Keyword Bank
Data Hosting – Cloud Hosting – File Hosting – Web Hosting – DSA – E-Commerce Directive – Article 6 DSA – Hosting Safe Harbour – Intermediary Liability – Actual Knowledge – Apparent Illegality – Notice and Action – Expeditious Removal – Active Role – Neutral Intermediary – No General Monitoring – Specific Monitoring – Injunction – Copyright Infringement – Defamation – Privacy – GDPR – Cybersecurity – Data Loss – Data Integrity – Contractual Liability – Tort/Delict – Causation – Damages – Service-Level Agreement – Backup Failure – Cloud Liability – Information Society Service – Fundamental Rights – Freedom of Expression – Cross-Border Liability – Territorial Injunction.

comments