Blog

Limits on the imposition of national obligations on digital service providers established in other Member States and the liability of intermediary service providers: Cases C-188/24 and C-190/24
The judgment of the Court of Justice of the European Union (hereinafter ‘CJEU‘) of 16 June 2026, delivered by the Grand Chamber in the joined cases C-188/24 and C-190/24, resolves the two questions referred for a preliminary ruling by the Conseil d’État, the French Council of State, which was hearing the two joined proceedings.
Although the original cases concerned two different issues -minors’ access to pornography and the notification of police checks via navigation apps- the CJEU decided to join the two cases as they essentially raised the same legal question: to what extent a Member State may impose specific obligations on information society service providers established in another Member State, without infringing Article 3 of Directive 2000/31 on certain legal aspects of information society services, in particular electronic commerce, in the internal market (hereinafter the ‘E-Commerce Directive‘).
The Conseil d’État asked, in essence, whether the national regulations it was applying -and which were the subject of the application for annulment- fell within the ‘coordinated field’ of Article 2(h) of the E-Commerce Directive and whether they constituted ‘requirements’ relating to the exercise of the right of access to the activity of an information society service within the meaning of the Directive. Furthermore, Case C-190/24 alone sought an interpretation of the liability regime for intermediary service providers (Article 15 of the Directive). It asked, in essence, whether Articles 14 and 15 of the E-Commerce Directive must be interpreted as meaning that the operator of an electronic driving assistance or geolocation navigation service falls within the scope of those provisions, and whether Article 15 precludes national legislation which allows such an operator to be prohibited from transmitting information relating to certain roadside checks.
Firstly, the CJEU groups the first three questions in Case C-188/24 and the first two in Case C-190/24 into a single question as to whether the E-Commerce Directive precludes a Member State from imposing on information society service providers established in other Member States a general and abstract criminal law obligation, designed to prevent minors from accessing pornographic content (Case C-188/24), and from prohibiting those providers from retransmitting information relating to certain roadside checks (Case C-190/24).
Article 3 of the Directive provides that each Member State must ensure that information society services provided by a service provider established within its territory comply with the national provisions applicable in that Member State which fall within the ‘coordinated field’. This scope is defined in Article 2(h) of the Directive, which states that it is limited to “the requirements imposed on service providers under the legal regimes of the Member States applicable to information society service providers in respect of information society services, regardless of whether they are of a general nature or specifically aimed at such services“.
The CJEU holds that it must be determined whether, in the light of Article 2(h) of the Directive, the coordinated scope is limited in two respects: (i) to the requirements and matters governed by the harmonisation provisions contained in Chapters II and III of the Directive; and (ii) in such a way as to exclude general and abstract provisions of criminal law or those pursuing objectives of public order, security and protection. This would confirm that the legislation at issue in the main proceedings does not fall within the scope of the mechanism established in Article 3 of that Directive.
The CJEU concludes that the scope of coordination is not limited in either of the two respects raised. On the one hand, it points out that it is not restricted to the matters harmonised by Chapters II and III of the Directive, since neither does the wording of Article 2(h) require this, nor would it make sense for the Annex to the Directive to expressly exclude certain non-harmonised matters from the mechanism set out in Article 3 if that scope were already limited, from the outset, to harmonised matters. On the other hand, it determines that the criminal, general and abstract nature of a provision, or its purpose relating to public policy and public security, does not automatically exclude it either; rather, only the matters specifically listed in Article 1(5) (taxation, data protection, cartels, etc.) are excluded, none of which are applicable in these cases. In fact, Article 3(4) itself provides for exceptions to the country -of-origin principle precisely on grounds of public policy and public security, which confirms that these matters do form part of the coordinated scope. On this basis, the CJEU concludes that the disputed French regulations fall within the coordinated scope insofar as they impose requirements relating to access to or the provision of an information society service.
Furthermore, the CJEU examines whether the obligations at issue constitute a requirement within the meaning of Article 2(h)(i) of the Directive. Regarding age verification, it concludes that this mechanism sets out the conditions for users’ access to the service and therefore does constitute such a requirement. As regards the ban on retransmission imposed on Coyote System, it classifies this as a requirement relating to the content of the service, as it restricts an existing functionality of the service. Consequently, the CJEU concludes that both sets of regulations impose requirements relating to the exercise of the activity which fall within the ‘coordinated field’ and are subject to the mechanism set out in Article 3(1) and (2) of the Directive.
The CJEU then confirms that both sets of rules restrict the freedom to provide services, as they also apply to service providers established in other Member States, which requires an assessment of whether the three cumulative conditions set out in Article 3(4) of the Directive are met to derogate from that principle. The conditions are that the measure must be necessary on grounds of public policy, public security, consumer protection and public health; that it must be directed against a specific service posing a risk; and that it must be proportionate. Regarding the second requirement, the CJEU holds that a general and abstract provision, such as the relevant article of the French Criminal Code, does not satisfy it. However, individual enforcement measures directed against a specific service provider, as in the case of Coyote System, do meet this requirement. As regards proportionality, the CJEU links this to the protection of fundamental rights recognised in the Charter of Fundamental Rights of the European Union and to the measures already provided for in the applicable sectoral legislation, considering that an additional requirement is proportionate where the service provider has not already adopted such measures. Applying this criterion, it considers the requirement for age verification to be proportionate and, subject to review by the national court, also the prohibition imposed on Coyote System.
Based on all this, it concludes that the Directive precludes the imposition of a general and abstract criminal liability on service providers from other Member States, but does not preclude a Member State, provided those conditions are met, from requiring a specific service provider to implement an age verification system, nor from prohibiting that provider from broadcasting information on roadside checks for reasons of public order, security or protection.
Finally, the CJEU addresses the third question referred for a preliminary ruling, raised solely in Case C-190/24, concerning the liability regime for intermediary service providers. The French Council of State had started from the premise that Coyote System fell within the definition of a hosting service provider under Article 14(1) of the Directive and asked only whether Article 15 precluded the prohibition on retransmission. However, the CJEU examines whether that premise is correct and, consequently, reformulates the question in two stages. The first stage seeks to determine whether the operator actually falls within the scope of Article 14(1) and then examines whether Article 15(1) precludes the prohibition at issue.
Firstly, the CJEU points out that the exemption under Article 14 only protects service providers acting neutrally; that is to say, where their conduct is purely technical, automatic and passive, meaning that they have neither knowledge of nor control over the content they store. In this regard, it clarifies that knowledge and control are alternative and mutually independent conditions; consequently, the mere existence of control over the stored information -even in the absence of actual knowledge due to the automation of the processing- is sufficient to exclude the operator from that exemption. The CJEU therefore establishes a key criterion for services that operate via algorithms: “if, beyond the mere classification and indexing of information for the purpose of improving its accessibility, the algorithm used determines, in the interests of the operator or its service, under what conditions, how and in what order of priority that information is or is not be broadcast, that operator exercises control over that information” (paragraph 112) and ceases to qualify as a hosting service provider. The consequence is that, in such a case, the protection afforded by Article 15(1) of the Directive does not apply either, as this provision applies only to providers who do fall within the scope of Article 14. However, the CJEU considers that it is for the French Council of State, the referring court, to ascertain whether Coyote System’s algorithm exercises such control.
Secondly, if the referring court were to conclude that Coyote System’s function is neutral and falls within the scope of Article 14(1), the CJEU examines whether the ban on retransmission can be justified under Article 14(3) -which allows the authorities to require the cessation or prevention of an infringement, even where the service provider is not liable- and whether it is contrary to Article 15(1). On this last point, it points out that the prohibition on imposing a general obligation to monitor does not affect obligations relating to a specific case, and that an order which can be complied with using automated tools, without requiring the service provider to carry out an independent assessment of all the content it manages, does not amount to general monitoring. Applying this criterion, the CJEU emphasises that the operator can comply with the prohibition without needing to know the content of its users’ messages; consequently, the information concerned is sufficiently defined to be blocked automatically.
In short, the CJEU concludes that an operator which algorithmically controls, in its own interest, the conditions under which information is disseminated cannot be classified as a hosting service provider and, therefore, Article 15 does not apply to it. It also considers that, in any event, the Directive does not preclude a Member State from prohibiting, on grounds of public order, security or defence, operators of this type of information society service, within the meaning of Article 14(1), from broadcasting information relating to certain roadside checks.
