Civil Law And Data Hosting Service Liability Claims In Europe .

Civil Law and Data Hosting Service Liability Claims in Europe

1. Introduction

Data hosting service liability concerns the civil and regulatory responsibility of a provider that stores data, files, applications, websites, databases, images, videos, communications or other information on behalf of customers or users.

Examples include:

  • cloud-storage providers;
  • web-hosting companies;
  • file-hosting platforms;
  • video-sharing platforms;
  • online marketplaces storing seller information;
  • social-media platforms;
  • enterprise cloud providers;
  • database-hosting providers;
  • application-hosting providers.

The central legal question is:

When should a hosting provider be responsible for unlawful, harmful, inaccurate, infringing or dangerous information stored on its infrastructure by another person?

European law has historically attempted to balance two competing interests:

Protection of victims
against
Protection of neutral intermediaries from unlimited liability.

The older framework was principally Article 14 of the E-Commerce Directive 2000/31/EC. Since 17 February 2024, the Digital Services Act (DSA), Regulation (EU) 2022/2065, has become the central EU framework for intermediary services, including hosting services. Article 6 DSA contains the hosting liability exemption, while also preserving the possibility of judicial or administrative orders to terminate or prevent infringements.

2. Meaning of a Data Hosting Service

A hosting service generally involves:

Storage of information provided by a recipient of the service.

Examples:

Cloud storage

A customer uploads files to a cloud platform.

Website hosting

A customer stores a website and associated databases on a hosting provider's servers.

File hosting

Users upload documents, photographs, videos or other files.

Platform hosting

A platform stores user-generated content.

Application hosting

A provider stores and runs software and associated customer data.

Database hosting

A provider maintains databases containing customer information.

3. Basic Liability Model

The basic relationship can be represented as:

User/customer

↓

uploads or provides information

↓

Hosting provider

↓

stores information

↓

third party suffers harm

↓

Potential civil claim

The important question is whether the provider merely supplied storage infrastructure or whether its conduct went beyond neutral hosting.

4. European Legal Framework

A. Digital Services Act

The principal modern EU instrument is:

Regulation (EU) 2022/2065 — Digital Services Act (DSA).

Article 6 provides a liability exemption for hosting services where the provider does not have actual knowledge of illegal activity or illegal content and, concerning claims for damages, is not aware of facts or circumstances from which the illegality is apparent; once the provider obtains the required knowledge or awareness, it must act expeditiously to remove or disable access.

This creates a fundamental structure:

No relevant knowledge → safe harbour

Relevant knowledge → prompt action required

5. Important Point: Hosting Does Not Mean Automatic Immunity

A provider cannot simply say:

“We are a hosting company, therefore we can never be liable.”

The legal analysis asks:

  1. Is the service actually a hosting service?
  2. Is the provider covered by the relevant liability exemption?
  3. Did the provider have actual knowledge?
  4. Was there sufficient information to establish apparent illegality?
  5. Did the provider respond expeditiously?
  6. Did the provider itself play an active role?
  7. Is a separate cause of action available?
  8. Is the claim about third-party content or the provider's own conduct?

The CJEU has repeatedly emphasised that intermediary liability protection depends upon the nature of the provider's activity and the statutory conditions.

6. Historical E-Commerce Directive

Before the DSA, Article 14 of Directive 2000/31/EC provided the principal EU hosting safe harbour.

The provider generally avoided liability where:

  • it lacked actual knowledge of illegal activity/information; or
  • it lacked awareness of facts or circumstances making illegality apparent; and
  • after obtaining the necessary knowledge, it acted expeditiously to remove or disable access.

The DSA has replaced the E-Commerce Directive's former intermediary liability provisions at EU level, but the extensive CJEU case law under the earlier framework remains highly important for understanding concepts such as hosting, knowledge, active role and injunctions.

7. Types of Data Hosting Liability

7.1 Copyright infringement

A user may upload:

  • films;
  • music;
  • books;
  • photographs;
  • software;
  • databases.

The copyright owner may seek relief against the hosting provider.

7.2 Defamation

A user might upload defamatory information to a hosted website.

The victim may seek:

  • removal;
  • injunction;
  • damages;
  • identification of the uploader where legally available.

7.3 Privacy violations

Hosted data may contain:

  • private photographs;
  • personal information;
  • medical information;
  • financial information;
  • confidential correspondence.

7.4 Data-protection violations

A hosting provider may become involved in disputes concerning:

  • unlawful processing;
  • inadequate security;
  • unauthorised disclosure;
  • data breaches;
  • retention;
  • access rights.

7.5 Trade-secret violations

A hosted file may contain:

  • source code;
  • manufacturing plans;
  • business strategies;
  • customer databases;
  • confidential contracts.

7.6 Illegal goods or services

A platform may store listings concerning unlawful products or services.

7.7 Cybersecurity-related harm

A compromised hosting account could facilitate:

  • malware distribution;
  • ransomware;
  • phishing;
  • credential theft;
  • botnet activity.

The provider's civil liability depends upon the particular contractual, statutory and tort/delict duties involved.

8. Hosting Provider vs Active Service Provider

This is one of the most important distinctions.

Neutral provider

The provider:

  • stores information;
  • operates servers;
  • supplies technical infrastructure;
  • performs automated processing;
  • does not determine the substance of the information.

Active provider

The provider may:

  • select content;
  • modify content;
  • optimise content;
  • promote particular content;
  • control information;
  • exercise editorial influence;
  • acquire knowledge of particular illegal content.

The CJEU's earlier case law explains that intermediary exemptions were directed at providers whose activity was essentially technical, automatic and passive rather than providers exercising knowledge or control over the information.

9. Actual Knowledge

Actual knowledge is crucial.

Suppose a hosting company receives a sufficiently specific notice:

“This particular file at this particular address contains an unauthorised copy of my copyrighted work.”

The provider may then need to examine the notification and take appropriate action under the applicable legal regime.

A vague statement such as:

“Your website contains illegal material”

may present a different legal problem.

The adequacy of notice is therefore important.

10. Notice-and-Action

A simplified model is:

Illegal content

↓

Specific notification

↓

Provider obtains relevant knowledge

↓

Provider investigates/assesses

↓

Removal or disabling of access

↓

Potential restoration where justified

The DSA retains the fundamental requirement that a hosting provider act expeditiously after obtaining the relevant knowledge or awareness.

11. Civil Damages

A claimant seeking damages may have to establish:

1. Duty

The provider owed a legally recognised duty.

2. Breach

The provider failed to comply with that duty.

3. Causation

The breach caused the loss.

4. Damage

The claimant suffered legally recoverable harm.

5. Absence of applicable immunity

The provider cannot successfully rely upon the applicable hosting exemption.

12. Contractual Liability

A customer may sue the hosting provider under a service agreement.

Typical contractual obligations include:

  • server availability;
  • data security;
  • backup;
  • confidentiality;
  • disaster recovery;
  • service levels;
  • data integrity;
  • restoration;
  • cybersecurity;
  • deletion;
  • migration.

For example:

A company stores its business database with a cloud-hosting provider. The provider fails to maintain agreed backups, and a server failure permanently destroys the customer's data.

This is fundamentally different from a claim concerning unlawful third-party content.

The provider may therefore have contractual liability even where intermediary safe-harbour rules concerning third-party content are irrelevant.

13. Tort / Delict Liability

National civil laws may recognise liability for:

  • negligence;
  • unlawful interference;
  • breach of statutory duties;
  • culpa;
  • defective security;
  • privacy violations;
  • property damage;
  • economic loss.

The exact requirements differ among European jurisdictions.

14. Data Loss Claims

A hosting provider can face a claim where customer data is:

  • accidentally deleted;
  • corrupted;
  • overwritten;
  • encrypted through ransomware;
  • made unavailable;
  • improperly migrated.

Potential questions include:

  1. Was backup contractually required?
  2. Was redundancy promised?
  3. Were recovery procedures adequate?
  4. Did the customer follow security instructions?
  5. Was the incident foreseeable?
  6. Did force majeure apply?
  7. What was the customer's actual financial loss?

15. Cybersecurity Hosting Claims

Suppose:

Company A → stores database with Cloud Provider B

A hacker compromises the provider's infrastructure.

The customer's database is stolen.

Possible legal claims concern:

  • security obligations;
  • contractual warranties;
  • negligence;
  • GDPR;
  • confidentiality;
  • incident response;
  • allocation of cyber risk.

The existence of a cyberattack does not automatically establish provider liability.

The claimant may have to establish that the provider's security failure contributed causally to the loss.

16. Important Case Law

The following cases are particularly useful for European hosting-liability analysis. The first group establishes the EU intermediary/hosting principles; the later cases demonstrate their application to injunctions, copyright and platform liability.

Case 1 — Google France and Google

Joined Cases C-236/08 to C-238/08, Google France and Google Inc. v Louis Vuitton Malletier SA and Others
CJEU, 23 March 2010

This is one of the foundational EU intermediary-liability cases.

The litigation concerned Google's AdWords service and trademark-related advertisements.

The CJEU considered the conditions under which an information-society service provider could benefit from the hosting safe harbour.

Principle

The provider's activity must be sufficiently neutral.

Where the provider plays an active role giving it knowledge or control over the stored data, the hosting exemption may not apply in the same manner.

Importance

The case establishes an important distinction between:

technical hosting

and

active involvement in stored information.

That distinction remains fundamental to modern data-hosting liability analysis.

Case 2 — L'Oréal v eBay

Case C-324/09, L'Oréal SA and Others v eBay International AG and Others
CJEU, 12 July 2011

Facts

L'Oréal alleged trademark infringement involving goods sold through eBay.

The CJEU considered:

  • intermediary liability;
  • hosting;
  • trademark infringement;
  • injunctions against intermediaries.

Principle

An intermediary that plays an active role in relation to information may fall outside the hosting exemption.

The Court also considered circumstances in which courts can grant injunctions against intermediaries.

Importance for data hosting

This case demonstrates that storage alone does not settle the liability question.

The court must examine what the provider actually does.

It is therefore highly relevant to:

  • cloud platforms;
  • online marketplaces;
  • managed hosting;
  • content platforms;
  • database-hosting services.

Case 3 — Scarlet Extended v SABAM

Case C-70/10, Scarlet Extended SA v SABAM
CJEU, 24 November 2011

This case concerned an injunction requiring an internet service provider to install a system for filtering electronic communications to prevent copyright infringement.

The CJEU rejected the requirement for a general and permanent filtering system of the type proposed because it conflicted with EU law and fundamental rights.

Principle

A hosting/intermediary provider cannot ordinarily be subjected to an unlimited obligation to monitor all communications in advance.

Importance

This is extremely important for data-hosting providers.

It establishes a distinction between:

specific removal obligations

and

general monitoring obligations.

Case 4 — SABAM v Netlog

Case C-360/10, Belgische Vereniging van Auteurs, Componisten en Uitgevers CVBA (SABAM) v Netlog NV
CJEU, 16 February 2012

Facts

Netlog operated an online social-networking platform.

SABAM sought an injunction requiring the platform to prevent copyright infringement by its users.

Decision

The CJEU rejected the imposition of a general filtering obligation comparable to the one considered in Scarlet Extended.

Principle

A hosting platform cannot generally be forced to install a broad preventive monitoring system covering all users and all content.

Relevance

The case remains important for:

  • cloud platforms;
  • social networks;
  • file-hosting systems;
  • user-generated-content platforms.

It illustrates the importance of balancing intellectual-property enforcement with:

  • privacy;
  • freedom of expression;
  • freedom to conduct a business.

Case 5 — Glawischnig-Piesczek v Facebook Ireland

Case C-18/18, Eva Glawischnig-Piesczek v Facebook Ireland Limited
CJEU, 3 October 2019

This is a major case on removal and injunctions against hosting providers.

The dispute arose after defamatory material was posted on Facebook.

The CJEU considered whether an Austrian court could require Facebook to remove unlawful content and prevent equivalent content from being reposted.

Principle

The absence of a general monitoring obligation does not prevent courts from imposing specific and sufficiently defined injunctions.

The Court recognised that a hosting provider can, in appropriate circumstances, be required to remove:

  • the specific unlawful information; and
  • information that is equivalent to it.

The judgment expressly addressed Articles 14, 15 and 18 of the E-Commerce Directive.

Importance

This case demonstrates the important boundary:

No general surveillance duty

does not mean

no removal duty after unlawful content has been identified.

Case 6 — YouTube and Cyando

Joined Cases C-682/18 and C-683/18, Frank Peterson v Google LLC, YouTube LLC and Others; Elsevier Inc. v Cyando AG
CJEU, 22 June 2021

This is one of the most important modern cases involving video-sharing and file-hosting platforms.

The Court examined:

  • copyright infringement;
  • hosting;
  • platform liability;
  • communication to the public;
  • Article 14 safe harbour;
  • injunctions.

The CJEU held that the operators of such platforms do not, merely by making their platforms available, necessarily carry out a copyright-relevant act of communication to the public for every unlawful upload by users. The hosting exemption and the conditions surrounding it remained important.

Importance

The case is highly relevant to:

  • file-hosting platforms;
  • cloud storage;
  • video hosting;
  • user-generated content;
  • copyright disputes.

It also emphasised the significance of whether the provider had specific knowledge of infringements and whether it acted after notification.

Case 7 — WebGroup Czech Republic and Others

Joined Cases C-188/24 and C-190/24
CJEU, 16 June 2026

This is particularly important because it reflects the current post-DSA legal landscape.

The CJEU considered the concept of hosting and intermediary liability in the context of services involving storage and dissemination of information.

The Court reiterated that merely storing information is not enough, by itself, to establish that every such service qualifies for the hosting exemption. The relevant intermediary character and statutory conditions must be examined.

Importance

This is useful for modern data-hosting litigation because it demonstrates that:

“Our servers store data” is not, by itself, a complete legal defence.

The nature and functioning of the service must be examined.

Case 8 — AGCOM (Online Gambling)

Case C-421/24, AGCOM (Online gambling)
CJEU, 16 July 2026

The Court addressed liability of Google in relation to YouTube videos promoting online gambling and considered the hosting-service exemption.

The case involved an Italian regulatory decision imposing a fine and removal obligations concerning videos uploaded by a content creator who had a commercial relationship with Google. The Court examined the relevance of Google's involvement with the content and the hosting liability framework.

Importance

This is particularly useful for modern platform cases because it shows that:

  • commercial relationships matter;
  • content-related involvement matters;
  • hosting cannot be analysed purely by looking at the technical fact of storage.

It is therefore a useful current authority when analysing whether a sophisticated platform remains within a hosting safe harbour.

17. Case-Law Summary Table

CaseCourtMain issueImportance
Google France v Louis Vuitton C-236/08–C-238/08CJEUHosting and active roleNeutrality vs active involvement
L'Oréal v eBay C-324/09CJEUMarketplace hosting and injunctionsActive role and intermediary responsibility
Scarlet Extended v SABAM C-70/10CJEUGeneral filteringNo general monitoring obligation
SABAM v Netlog C-360/10CJEUSocial-network filteringProtection against general surveillance
Glawischnig-Piesczek v Facebook C-18/18CJEUDefamatory content and injunctionsSpecific/equivalent-content removal
YouTube and Cyando C-682/18 & C-683/18CJEUVideo/file hostingPlatform and copyright liability
WebGroup Czech Republic C-188/24 & C-190/24CJEUModern hosting/intermediary statusCurrent interpretation
AGCOM (Online gambling) C-421/24CJEUYouTube hosting liabilityCurrent post-DSA relevance

18. Data Hosting and Copyright

Copyright is one of the most developed areas of hosting litigation.

A user uploads:

“Movie_X.mp4”

The copyright owner alleges infringement.

Three questions arise:

Question 1

Did the user infringe copyright?

Question 2

Is the hosting provider itself legally responsible?

Question 3

What action can a court require from the provider?

Cases such as L'Oréal, Scarlet Extended, Netlog, Glawischnig-Piesczek and YouTube/Cyando help answer these questions.

19. Defamation and Hosting

Suppose a user uploads:

“Company X commits fraud.”

The company demands removal.

The hosting provider must consider:

  • whether the content is unlawful;
  • whether the notification provides sufficient information;
  • whether a court order exists;
  • whether the provider has relevant knowledge;
  • whether removal is required;
  • whether freedom of expression is implicated.

Glawischnig-Piesczek is especially important because it demonstrates that a court may require specific removal and prevention of equivalent unlawful material without imposing an unlimited general monitoring obligation.

20. Data Protection and Hosting

Hosting providers may process enormous amounts of personal data.

Possible liability issues include:

  • unauthorised disclosure;
  • inadequate technical safeguards;
  • unlawful access;
  • retention;
  • deletion;
  • data-subject rights;
  • processor/controller allocation;
  • cross-border transfers.

A hosting provider can therefore face two different legal dimensions:

Platform/intermediary liability

Liability for information supplied by users.

Data-protection liability

Liability arising from the provider's own processing of personal data.

These should not be automatically merged.

21. Cybersecurity Liability

Consider:

A cloud provider promises industry-standard security.

A ransomware attack compromises the provider's infrastructure.

The customer's confidential database is encrypted and unavailable for 15 days.

The customer claims:

  • breach of contract;
  • negligence;
  • failure to maintain reasonable security;
  • business interruption losses;
  • restoration expenses.

The provider may defend itself by arguing:

  • security complied with contractual standards;
  • attack was sophisticated;
  • customer security controls were defective;
  • loss was too remote;
  • contractual liability limits apply;
  • force majeure;
  • causation is not established.

22. Data Integrity

Hosting liability can also arise where data is altered rather than merely disclosed.

Examples:

  • incorrect database migration;
  • corrupted records;
  • failed synchronisation;
  • unauthorised modification;
  • software incompatibility;
  • failed backup restoration.

The central question becomes:

Did the provider have a legal obligation to preserve the integrity and availability of the data?

23. Service-Level Agreements

Large cloud-hosting agreements often contain:

  • uptime guarantees;
  • backup obligations;
  • disaster recovery;
  • recovery-point objectives;
  • recovery-time objectives;
  • cybersecurity obligations;
  • incident notification;
  • service credits;
  • liability caps.

A civil claim may therefore be determined primarily by the contract, rather than by intermediary safe-harbour law.

This distinction is essential.

24. Liability for Customer Data vs Third-Party Data

Situation A — Customer's own data

A company pays for hosting.

The provider loses the company's database.

This is principally a:

contractual/service-liability dispute.

Situation B — Third-party unlawful content

A user uploads defamatory or infringing material.

This is principally an:

intermediary/hosting-liability dispute.

Situation C — Provider's own conduct

The provider actively modifies, promotes or controls information.

This may weaken or remove reliance on hosting protection.

25. Notice Requirements

A good notice should ideally identify:

  • exact URL;
  • exact file;
  • specific unlawful content;
  • legal basis;
  • ownership/right;
  • evidence;
  • contact information;
  • requested remedy.

A vague notification creates greater difficulty in determining whether the provider has obtained legally relevant knowledge.

26. General Monitoring vs Specific Monitoring

This distinction is extremely important.

General monitoring

“Check every file uploaded by every customer.”

EU law has historically resisted imposing such broad obligations on intermediary providers. Scarlet Extended and Netlog are central authorities.

Specific monitoring/removal

“This particular file has been judicially determined to be unlawful. Remove it and prevent its equivalent reposting.”

This can be permissible under the principles developed in Glawischnig-Piesczek.

27. Fundamental Rights

Hosting disputes involve competing rights.

Victim

Right to:

  • property;
  • reputation;
  • privacy;
  • effective remedy.

User

Right to:

  • freedom of expression;
  • privacy;
  • information.

Hosting provider

Right to:

  • conduct a business;
  • avoid disproportionate regulatory burdens.

The CJEU's intermediary cases repeatedly require these interests to be balanced.

28. Territorial Scope

A hosting provider may operate:

  • servers in Germany;
  • customers in France;
  • headquarters in Ireland;
  • users across Europe.

A court may therefore have to consider:

  • jurisdiction;
  • applicable law;
  • territorial scope of injunctions;
  • recognition and enforcement;
  • GDPR territorial rules;
  • DSA obligations.

Glawischnig-Piesczek is especially significant because it considered the possible personal, material and territorial scope of injunctions against hosting providers.

29. Defences Available to Hosting Providers

29.1 Hosting safe harbour

The provider may argue that it satisfies Article 6 DSA.

29.2 Lack of knowledge

The provider may argue:

“We did not know about the unlawful information.”

29.3 Prompt action

The provider may establish:

“Once we received sufficient notice, we removed or disabled access promptly.”

29.4 Neutral technical role

The provider may demonstrate that it:

  • merely stored information;
  • did not select it;
  • did not control it;
  • did not actively participate in the unlawful conduct.

29.5 Causation

The provider may argue that the claimant's loss resulted from the customer's or user's conduct rather than the hosting service.

29.6 Contractual limitations

Business-to-business agreements may contain:

  • liability caps;
  • exclusions;
  • indemnity clauses;
  • service-credit provisions.

Their enforceability depends upon applicable national law and the particular contract.

30. Remedies

Potential remedies include:

Damages

Compensation for proven loss.

Injunction

Order requiring removal or prevention of specific unlawful information.

Declaration

Court declaration concerning rights or obligations.

Restitution

Recovery of improperly retained benefits where applicable.

Specific performance

Potentially relevant to contractual hosting obligations.

Removal or disabling

Particularly relevant to unlawful third-party content.

Regulatory penalties

The DSA and national legal systems may provide regulatory consequences separate from private civil damages.

31. Hypothetical Example

Suppose Company A stores its customer database with Hosting Company B.

A hacker gains access because B failed to patch a known vulnerability.

The hacker steals:

  • customer names;
  • addresses;
  • financial information.

Company A suffers:

  • investigation expenses;
  • business interruption;
  • customer claims;
  • reputational damage.

Company A may examine:

Contract

Did B promise a particular security standard?

Negligence

Was the vulnerability reasonably foreseeable?

Causation

Did B's failure cause the breach?

Data protection

Were statutory security requirements breached?

Damages

Which losses are legally recoverable?

This is different from a case where Company A's customer uploads unlawful information to B's servers.

32. Practical Litigation Checklist

A claimant should collect:

  1. Hosting agreement.
  2. Terms of service.
  3. SLA.
  4. Security specifications.
  5. Backup policy.
  6. Incident reports.
  7. Server logs.
  8. Access logs.
  9. Vulnerability reports.
  10. Notification records.
  11. Removal requests.
  12. Correspondence.
  13. Expert cybersecurity evidence.
  14. Evidence of financial loss.
  15. Evidence of causation.

33. Core Legal Test

A simplified European hosting-liability analysis is:

1. Is there hosting?

↓

2. What information was stored?

↓

3. Who supplied it?

↓

4. Is it unlawful?

↓

5. Did the provider have actual knowledge?

↓

6. Was illegality apparent from the relevant facts?

↓

7. Did the provider act expeditiously?

↓

8. Did the provider play an active role?

↓

9. Is there a separate contractual/tort/data-protection duty?

↓

10. Did the claimant suffer legally recoverable damage?

↓

11. Is causation established?

↓

12. What remedy is available?

34. Conclusion

European data-hosting liability is based on a conditional intermediary-liability system, not absolute immunity.

The basic principle is:

A hosting provider should not automatically become liable merely because unlawful information is stored on its infrastructure by a user.

At the same time:

A provider cannot necessarily rely on hosting protection where it has the legally relevant knowledge and fails to act, or where its own active involvement, contractual obligations or other legal duties create liability.

The most important authorities are Google France, L'Oréal v eBay, Scarlet Extended, SABAM v Netlog, Glawischnig-Piesczek, and YouTube/Cyando, with the 2026 WebGroup Czech Republic and AGCOM (Online gambling) judgments particularly useful for understanding the evolving modern framework. The older CJEU cases remain important, but their reasoning must now be read alongside the DSA's autonomous liability regime.

Exam Keyword Bank

Data Hosting – Cloud Hosting – File Hosting – Web Hosting – DSA – E-Commerce Directive – Article 6 DSA – Hosting Safe Harbour – Intermediary Liability – Actual Knowledge – Apparent Illegality – Notice and Action – Expeditious Removal – Active Role – Neutral Intermediary – No General Monitoring – Specific Monitoring – Injunction – Copyright Infringement – Defamation – Privacy – GDPR – Cybersecurity – Data Loss – Data Integrity – Contractual Liability – Tort/Delict – Causation – Damages – Service-Level Agreement – Backup Failure – Cloud Liability – Information Society Service – Fundamental Rights – Freedom of Expression – Cross-Border Liability – Territorial Injunction.

LEAVE A COMMENT