19 December 2025
In its judgment C-492/23 of 2 December 2025 (Russmedia), the European Court of Justice examined whether a hosting provider, namely Russmedia, must proactively take action against content that violates personality rights if it qualifies as a controller under data protection law. Some interpret this ruling as the end of the liability privilege, which requires such service providers to take action against illegal content that is unknown to them only after receiving a notification (notice-and-take-down)**. However, this appears to be based on a misunderstanding of the ECJ's reasoning.
In this article, we will assess this reasoning and also explain the corresponding legal situation in Switzerland.
The eCommerce Directive, in force since 2000, already introduced the principle of "no liability without knowledge" in the EU. In short, this principle means that a service provider is not liable for user-published content if:
This privilege is justified by the fact that the hosting provider plays a purely passive, technical, and neutral role.
The Digital Services Act (DSA) has since incorporated this liability rule, which continues to apply there in the same form.
The case originated from an advertisement on an online portal operated by Russmedia. An anonymous user posted an ad (falsely) offering sexual services, using the data subject's real and her private mobile phone. Although Russmedia promptly removed the advertisement upon the data subject's request, she subsequently sued Russmedia for non-material damages. After proceedings through several national courts the case reached the ECJ.
The ECJ was asked to clarify the following problem: Can a hosting provider that also commercially uses content published by its users still benefit from the liability privilege, or must it ensure compliance with data protection law (namely the General Data Protection Regulation, GDPR) in connection with the personal data published on its platform?
First of all, the ECJ concluded that Russmedia is considered a (joint) controller under data protection law for the content published on its online portal. Specifically, Russ media's terms of use reserved the right to "use, distribute, transmit, reproduce, modify, translate, pass on to partners and remove at any time" published content. The Court found this reservation alone provided decisive "indications" that Russmedia processes the data not only for the advertising user, but also for of its own commercial interest. thus participating in determining the purposes and means of the original publication. In addition, the ECJ's noted that Russmedia has a significant influence on the worldwide dissemination of the personal data contained in the advertisements by determining the parameters for their distribution on its platform according to the target audience and determining, among other things, the presentation and duration of the publication.
The supposed "bombshell" of the judgment, however, is the ECJ's subsequent conclusion that a hosting provider that is a controller for the published content under data protection law cannot invoke the liability privilege of the eCommerce Directive (now the DSA). In the ECJ's opinion, Russmedia should have proactively identified special categories of personal data (such as information about sexual life in this case) and ensured that only the data subject themselves or someone with their consent published it. Additionally, Russmedia should have used appropriate technical measures to prevent the copying and dissemination of this data.
The ECJ did not address whether Russmedia actually knew of the personal data in question, i.e., whether it actually used the disputed advertisement for its own commercial purposes. Rather, the ECJ based its view on the fact that Directive 95/46/EC (the GDPR's predecessor expressly excluded questions it covered from the scope of the eCommerce Directive (which was applicable at the time the disputed advertisement was published) (Art. 1(5)(b) and recital 14 of the eCommerce Directive).
The current DSA also expressly leaves the provisions of the GDPR unaffected (Art. 2(4)(g) DSA); it can therefore be assumed that the ECJ would have reached the same decision under the new DSA regime.
The judgment and its reasoning are comprehensible and ALIGN with the intentions of the European legislator.
However, the ECJ's reasoning omits an important point: A service provider can only benefit from the liability privilege under the eCommerce Directive/DSA if its service consists of "storing information provided by a user on their behalf" (cf. Art. 14(1) eCommerce Directive and Art. 3(g)(iii) DSA). The privilege therefore clearly relates only to the hosting itself.
This means the following:
It is important to note that the ECJ did not affirm Russmedia's role as a joint controller solely because the company reserved the right in its terms of use to use the third-party content for its own purposes; rather, it considers this as an indication. The decisive criterion for assuming joint responsibility was instead, in this case too, the active and determining participation in the publication of the user content, which resulted from the specific design and parameterisation of the platform. By creating the technical and organisational framework for the data publication and thus pursuing its own economic interests, Russmedia significantly influenced the purposes and means of the processing. Therefore, even applying the ECJ's case law in the Russmedia judgment, a service provider does not become a (joint) controller merely by contractually reserving the right to use published content for its own purposes; further co-determination is required.
The provision in the eCommerce Directive/DSA that the applicable data protection law remains unaffected, on which the ECJ relies in the Russmedia judgment, must also be understood against this background: Anyone who is obliged under the GDPR to ensure lawful data processing should not be able to evade this responsibility by invoking the liability privilege.
The above is likely to be primarily relevant for online marketplaces, social networks and similar services, as on the one hand these service providers have an inherent interest in organising and preparing user-published content , for example to increase the attractiveness of its own platform. On the other hand, the service provider on such platforms often have more influence over the design of data collection and processing than, for example, with a pure web-hosting provider, whose service is primarily limited to the provision of storage space.
The question therefore arises as to whether a service provider must confine itself to the purely passive, technical and automatic storage of information if it does not want to avoid liability for its users illegal content. Recital 22 of the DSA offers at least some guidance in this regard, stating that a hosting service provider may index and catalogue the information provided by users and stored at their instigation in order to make it findable via a search function integrated on its platform, without this alone imputing actual knowledge of the content. This clarification is crucial as it acknowledges that certain activities that go beyond pure storage are essential for the provision of a functional and user-friendly service. It can therefore be assumed that an additional function or service that goes beyond pure storage but still serves the user's purpose – namely the effective accessibility of their content to third parties – does not automatically disqualify the service provider from invoking the liability privilege. The decisive criterion is whether the service provider maintains a neutral, technical, and passive role or whether it assumes an active one that gives it knowledge of or control over the specific content. As long as an additional function (such as indexing) is automated and occurs without editorial or curatorial intervention that would suggest a substantive engagement with the content, the passive character of the service is maintained.
The parallel to data protection law, in particular the distinction between controller and processor, underpins this conclusion. If a hosting provider designs such an additional function or service in such a way that the associated processing of personal data is carried out exclusively for the purposes and on the instructions of the user, the hosting provider is not considered a controller from a data protection perspective, but a processor (see Art. 4 No. 8 GDPR). Classifying the hosting provider as a processor strongly indicates that it also assumes a passive role under today's DSA and can therefore invoke the liability privilege. The ECJ's reasoning in the Russmedia judgment reinforces this view.
In summary, it can be said that the "explosive force" of the Russmedia judgment lies not in the undermining the liability privilege, but rather in the fact that it takes up an aspect of provider liability that may have been overlooked in practice until now. In our opinion, it must continue to be possible for hosting providers to reserve the right to use the published user content themselves. However, in light of the ECJ's reasoning in the Russmedia ruling, it is advisable for hosting providers to clearly identify and delimit such uses as their own processing operations in order to reduce as far as possible the appearance of involvement in the publication of content by users.
In contrast to the EU, Switzerland has no specific liability regulation for hosting providers or similar service providers, such as is now enshrined in the DSA. The draft of the new Federal Act on Communication Platforms and Search Engines (CommPA; currently not available in English), which the Federal Council put out for consultation at the end of October 2025, only provides for an obligation on communication platforms to set up a reporting procedure, but no associated relief from liability.
Consequently, the civil liability of hosting providers for user content that violates personality rights is governed by the general provisions of tort law in Art. 41 et seq. of the Code of Obligations (CO), the protection of personality rights in Art. 28 et seq. of the Civil Code (CC) and the Data Protection Act (DPA). For claims by data subjects in the event of data protection violations that also constitute a violation of personality rights, the DPA refers back to the provisions of Art. 28 et seq. CC.
The interplay of these norms results in the following, differentiated regime of responsibility and liability:
Based on the points set out above, it is therefore probable that a Swiss court would reach a similar conclusion to the ECJ in the Russmedia case, provided that the hosting provider can be proven to be jointly responsibility for the publication of user content. We therefore advise Swiss hosting service providers to take steps to avoid, as far as possible, such (joint) responsibility for user content. This includes, among other things, clearly distinguishing between any use for the hosting provider’st own purposes and he publication by the user, so as not to give the impression of participation. If a participation and, therefore, joint responsibility is unavoidable (for example, because it is inherent in the business model), robust compliance processes should be implemented to meet hosting provider’s data protection obligations as a controller and thus minimise liability risks.
Author: Sarah Bischof