DMCA Review Begins. Watch the Red Flag.

Early last week, the Senate Judiciary Committee held the first in what will be a year-long series of hearings (roughly one per month) to review the Digital Millennium Copyright Act.  Almost as old as the publicly-available internet itself, the 1998 DMCA expressed the best efforts of Congress to predict how the digital market might evolve and to, therefore, strike a balance between the interests of internet service providers (ISPs) and copyright owners.

Over the intervening twenty-two years, much—MUCH—has been written, debated, shouted, flung, wailed, opined, and scorned about the DMCA, specifically Titles I and II of the five-title statute.  If we ask the tech-centric/copyright-skeptics, they are likely to say that Title I (§1201) is a disaster and that Title II (§512) is working just fine; while the creator/copyright proponent will tell us exactly the opposite. I cannot condense the number of issues raised in this first hearing alone into a single post—especially when §1201 and §512 address very different legal regimes—and it is far too early in the review process to respond to any specific proposals being made. 

What I will reiterate in this post is that the greatest concern to creators of every size is the conditional liability shield (“safe harbor”) provided to web platforms by §512.  It is the foundation of the oft-described “whack-a-mole” problem whereby the independent author attempts to remove infringing uses of her works one-by-one, only to have them reappear on the same platform(s) faster than she can prepare new notices.  (And “whack-a-mole” can be just as big a problem for a small business like an apparel maker as it is for a traditional artist like a musician.)  

In response to this futile battle with online infringement, authors often give up enforcement via the DMCA takedown process (resigned to donating even more revenue to billion-dollar corporations) while they ask as a community why the major platforms in particular cannot do a better job of preventing protected works from being chronically re-uploaded without license.  This second question is where we step into a BIG policy kerfuffle with regard to §512, and I imagine it is a topic about which we are going to hear a lot of ideas and a lot of noise.  

This week’s hearing hosted two panels of witnesses, the first of which provided an overview as to how the DMCA came to be; while the second panel, comprising IP academics, provided some insight as to where the DMCA debate may be heading.  In the interest of keeping this post containable, I will focus on the testimonies of Professor Sandra Aistars of the George Mason School of Law and Professor Rebecca Tushnet of Harvard Law School, and the subject of “red flag” knowledge under the DMCA.  

What is “Red Flag” Knowledge?

Unfortunately, you will get different answers depending on whom you ask, including a court split on the matter if you ask either the Second or the Ninth Circuit Court of Appeals.  But in everyday life, “red flag” knowledge is a reasonable, common-sense inference that one can draw from a modest amount of empirical evidence and experience.  If you enter the house to find trash strewn across the floor and a chagrined puppy in the corner, you will not need training in forensic science to have “red flag” knowledge that either the dog has committed a misdemeanor, or he has been artfully framed by the cat.  

That roughly describes the degree of analysis Congress intended ISPs to perform when encountering evidence of copyright infringement on their platforms.  As Professor Aistars noted, “Although Congress did not obligate service providers to actively seek out infringements, it did require them to act expeditiously to remove infringing materials once they have knowledge or awareness of infringing activity on their networks.” (See companion Appendix describing basic ISP Conditions.)

For example, let us imagine that the users of a web platform we’ll call Vimeo are making videos using some famous music we’ll call Beatles songs.  Any ordinary observer can reasonably assume that these users probably did not license these sound recordings; yet in the case Capitol Records v. Vimeo, the Second Circuit held, on the issue of “red flag” knowledge, that the platform’s operators would have needed either legal or music-industry expertise in order to discover infringement.

Keeping in mind that voluntary removal of material based on “red flag” knowledge of infringement is a condition of an ISP’s “safe harbor,” decisions like Vimeo do more than erase this part of the statute—they exacerbate a culture of infringement through court-sanctioned willful blindness.  And as Aistars added in her testimony, “Pointedly, this occurred in a case where discovery had revealed emails from managers to employees winkingly encouraging infringement.”  Thus, Aistars is among those who would advocate clarifying the meaning of “red flag” to restore the intent of §512.

The Vimeo emails Aistars mentions are typical of the shoulder shrugs and middle fingers creators are used to receiving from many platform operators, and application of the DMCA to date has unquestionably fostered cultural attitudes anathema to the kind of cooperation between ISPs and rightsholders Congress specifically intended to promote two decades ago.  Further, unintended endorsement of this culture among site operators may be exacerbating a persistent misunderstanding among individual and commercial users that the internet is a realm of automatic immunity.  As I have described in several posts, this misconception can cause unnecessary trouble for both creators and users of protected works.

Responses to Fixing “Red Flag” 

Anticipating the likelihood that, if there is to be any revision to §512 at all, “red flag” will be a major point of debate, Professor Tushnet warned against what she and others see as throwing out the proverbial baby with the bathwater.  “If there is one message I would ask the members of the Committee to take away today,” she stated in her opening testimony, “it is that most beneficiaries of §512 are not Google or Facebook.”  Tushnet cautions that if we were to amend §512 solely as a response to the challenges creators face on very large, commercial platforms like YouTube, we risk simultaneously putting compliant, smaller platforms out of operation and facilitating even greater monopolization by the largest entities.

As a statistical matter, Tushnet is making a “few bad apples” argument, except for the fact that some of the baddest apples in the bunch happen to be the most powerful, wealthiest internet companies in the world.  So, even if we take her premise and data at face value (i.e. that millions of compliant sites rely on §512 to exist), this does not recommend ignoring the catalog of evidence that application of the DMCA has promoted willful blindness among the operators of major ISPs.  Simply put, if twenty-million sites operate without harm while one site does harm to twenty-million creators, we still have a problem if the law shields that one site from liability.  So, the status quo cannot be the final answer.  

As a practical consideration, Tushnet’s argument is based on the assumption that a more clearly defined restoration of the intent of “red flag” knowledge can only be implemented by technological measures, which only the largest ISPs can afford.  Hence, her argument that this will result in entrenching, for instance, YouTube’s monopoly position, notably glossing over the fact that there are other forces entrenching online monopolies.  While this technology-investment argument is worthy of discussion, the aforementioned Vimeo case is just one example in which the principle of “red flag” knowledge was obliterated in a purely human paradigm (i.e. human managers choosing not to see what was right in front of them).

Post Hoc Ergo Propter Hoc? (or not all good things come from §512.)

As Tushnet testified, her own Organization for Transformative Works site hosts over “four-million works” yielding 1.2 billion page views per month, while the site receives takedown notices at a rate of less than one per month, most of which are invalid.  Assuming these data are correct, the site to which she refers seems barely relevant as an example. It is a large fanfic platform with what appears to be a vast amount of material—mainly short works of written text—that is highly unlikely to infringe.  No sound recordings.  No photographs.  No film clips.  At most, some fanfic writer could maybe—and I mean maybe—run afoul of a derivative works right. 

From a cursory review of OTW, it is not at all evident that adopting a clearer, statutory definition of “red flag” (in order to hold the majors accountable) would force a site like this one to invest in prohibitively expensive technology in order to remain complaint.  If the platform is indeed receiving takedown notices at a rate of less than one valid notice per month, this is most likely evidence that the site hosts little to no infringing material—and that when notices are received, human review is sufficient to the task.  Further, the fact that the site hosts “fandoms” for a long list of works owned by major motion picture studios indicates that infringement must be very low to near zero if it has not invited the attention of an industry with the resources to send notices in volume.  

As is often the case, defenders of the status quo (the same is true for Section 230 of the CDA) will say “look at all the benefits this law has yielded” and then point to examples that, under scrutiny, do not necessarily rely on the liability shield so substantially as may be asserted.  In this vein, Tushnet’s testimony includes several references to all manner of good news about the creative industries—more movies, TV, music, etc. than ever before—but it would be a logical stretch to assert that, for instance, Billie Eilish’s YouTube-to-Grammy-Awards success story owes much at all to §512—let alone the collapse of the “red flag” principle. 

As Chairman Tillis noted, “this is a very wonky subject,” and that last description of mine was very wonky indeed; but DMCA review will be a devil-in-the-details story to watch.  Despite the hyperbole that will inevitably seep onto social media about these hearings, it is neither practical nor desirable for rightsholders to seek obliteration of the safe harbor altogether—that is not the goal.  But at the same time, it cannot be acceptable that a statute designed to mitigate copyright infringement and incentivize cooperation has served to reward infringement and position ISPs and rightsholders at permanent loggerheads.  


*This case is further complicated by a conflict between state and federal law over the use of sound recordings made prior to 1972, but that’s a whole other bowl of noodles. 

Photo source by Robertobinetti70

Appendix I to DMCA 2020: Section 512 “Safe Harbor” Conditions

May people know that online service providers are shielded from liability for copyright infringement by their users, meaning that a court will, on summary judgment, often excuse a web platform as a named defendant when an infringement has been committed by its customers.  Many people are not aware, however, that a service provider must meet certain conditions in order to remain protected by this “safe harbor.”  

These conditions are voluntary, and although failure to meet them does not automatically make a provider liable for infringement; non-compliance will—or is meant to—void the automatic protection in a potential litigation.  Below is a list of several–but not all–of the key conditions a service provider must meet under the DMCA statute Section 512, including an explanation of “red flag” knowledge:

THIRD-PARTY INFRINGEMENT — The infringing material must have been made available by users/customers.  

This is the foundation of 512—the very reasonable assumption by early online service providers (e.g. the Baby Bells) that users will inevitably transmit infringing material online.  If the platforms were held liable for infringement by its users, this would have stifled investment in developing many platforms that host User Generated Content (UGC).  Infringing material may not be made available by a service provider.  If a site operator directly uploads or transmits infringing material of its own volition, the “safe harbor” does not shield it from liability.

NOTICE & TAKEDOWN — The service provider must expeditiously remove infringing material upon receipt of a valid takedown notice sent by the copyright owner or their agent.  

Often simply called notice-and-takedown (or just takedown), sites that wish to maintain the protection of the “safe harbor” generally comply with this provision, though it is a subject of controversy on all sides.  For creators, sending takedown notices, one infringing use at a time, is the source of the “whack-a-mole” complaint.  For ISPs and some users, the takedown regime is often described as rife with abuse and error.  See post here responding to one “abuse” study cited by Professor Tushnet in her testimony at the first DMCA hearing 2020. 

REPEAT INFRINGERS — Develop and maintain a policy that includes account termination as a final step for repeat-infringers.  

This issue made big news when ISP Cox Communications lost two substantial lawsuits for failure to maintain such a policy.  While the DMC does not clearly define “repeat infringer” or dictate the design of a “repeat infringer policy,” it is usually some type scaled warning process (e.g. six-strikes), but which must result in account termination if the repeat infringer refuses to stop.  For instance, the courts found that Cox’s 14-strikes-and-they-will-eventually-reset-your-account process voided their “safe harbor” in court. 

KNOWLEDGE — Site operators are not required to search for infringement, but they must remove material upon obtaining knowledge that it is infringing.   

Because the knowledge conditions have largely been ignored in practice over the past 22 years, many people do not know they exist or what they are.  Codified in 512(c), the statute expressly states that the service provider “shall not be liable” if (1) its operators do not have actual knowledge of infringement; (2) its operators are not aware of facts or circumstances from which infringing activity is apparent; and (3) upon obtaining knowledge of infringement, expeditiously removes the relevant material.  

That second condition describing “facts or circumstances” is what we often refer to as “red flag” knowledge under the DMCA.  This is the “walks like a duck,” common-sense knowledge standard that has generally been erased from practice.  For instance, many cases and complaints involve famous works used in ways that any layperson could assume is unlicensed; or several famous litigations have found evidence of internal communications indicating that site operators had a pretty good idea that infringement was taking place. 

The Precarious Politics of Reigning in Silicon Valley

As our attention turned to concerns about disinformation, hate speech, and data security after the 2016 election, it became clear that the big cyber policy on deck was going to be a fight about Section 230 of the Communications Decency Act (1996).  For some detailed discussion about this legislation, see posts here, here, and here; but in nutshell, Section 230 shields online platforms against liability for potential harm that may result from the conduct of its users.  It is occasionally and improperly associated with copyright infringement, from which platforms are largely shielded by Section 512 of the DMCA (1998). 

Although 230 was never intended to provide blanket immunity for all sites hosting any kind of user-generated content, most courts over the 24 years since the law was adopted have interpreted it as a blanket immunity for all sites hosting any kind of user-generated content.  This includes content that may be posted for the express purpose of causing harm like harassment, defamation, revenge porn, fraud, or disinformation.  230 is the statutory reason why site owners respond with a shrug or, at best, a feeble explanation for hosting material that goes beyond mere offense, as we have seen its power to alter truth itself.  If you were mystified, for instance, by Zuckerberg’s sphinx-like reasoning that Facebook would maintain Holocaust denial pages because they are merely “misinformation and opinion” rather than “hate speech,” that was just one manifestation of the ideological flaw, which helped write Section 230 two decades ago.   

“We were naïve. We were naïve in a way that is even hard to recapture. We all thought that for people to be able to publish what they want would so enhance democracy and so inspire humanity, that it would lead to kind of flowering of creativity and emergence of a kind of a collective discovery of truth.”

Those are the words of former FCC Chairman Reed Hunt lately expressing regret for the adoption of Section 230, clearly identifying the erroneous underlying premise, which many critics now refer to as tech-utopianism.  And while it is somewhat encouraging to finally see a greater appetite for holding platforms accountable for some of their ill-effects, this mood change is anything but clearly definable.  Instead, we hear cacophony of disparate—even competing—rationales for reigning in Big Tech, and if this chaos cannot manifest as rational policy, Big Tech may win the status quo, which they spare no expense trying to maintain.   

For example, voices as incompatible as Vice-President Joe Biden and Senator Ted Cruz have both raised the specter of abolishing Section 230, but for very different reasons.  Biden and others see the liability shield as encouraging a platform like Facebook to continue hosting false information (e.g. Holocaust denial), while Cruz and other Republicans complain that social platforms are biased against conservatives.  But good luck trying to reckon with the devil in those details.

Would Biden include headlines or stories from left-leaning organizations that are inaccurate?  Would Cruz consider social media platforms removing Alex Jones, or the hosting providers dropping The Daily Stormer as examples of anti-conservative bias these days?  It becomes easy to imagine how a pragmatic and sober debate about Section 230 can get lost amid the inherent tribalism implied by just those two voices alone.

From a very different sector, David McCabe reports for the New York Times that a “motley” group of corporations, including Disney, IBM, and Marriott, are gunning for Section 230. “The companies’ motivations vary somewhat,” writes McCabe.  “Hollywood is concerned about copyright abuse, especially abroad, while Marriott would like to make it harder for Airbnb to fight local hotel laws. IBM wants consumer online services to be more responsible for the content on their sites.”

As prefaced above, note that even The New York Times will erroneously include copyright in a conversation about Section 230, though in fairness, the underlying principle—namely that no platform should ever be responsible for material published by users—is fundamentally the same in 230 as the DMCA’s 512.  Still, let us assume that especially because the Times used “Mickey Mouse” in the headline, this story will be interpreted by many as “Copyright maximalist Walt Disney Company wants to break the internet again,” or something to that effect.  And viola!  We are no longer having a conversation about platform responsibility. 

In a similar vein, the Center for Democracy and Technology published an article on its site criticizing a proposal introduced by Sen. Graham to combat child sexually abusive material online; and the article and associated tweet exploits distrust for both Graham and Attorney General Barr as reasons to fear the proposal itself.  Sure, I personally think Sen. Graham is the most prominent wuss in America today; and Bill Barr is batshit crazy, spluttering his views that people without religion lack moral judgment, but …

I don’t trust the folks at CDT either because they are ideologues too—OG tech-utopians who just happen to receive significant funding from Google.  (That, and I am very much opposed to child sexually abusive material.) So, whether the harm that needs addressing is child exploitation, revenge porn, online harassment, or mass disinformation campaigns, if we want to cope with any of these still somewhat novel challenges, we just might have to entertain the possibility that a sound policy proposal will come from some party we do not like in a different political context.

The subtle irony in this last example, of course, is that the folks at CDT would probably never entertain the notion that blanket platform immunity has been a major catalyst to creating the alternate realities that people like Graham and Barr now occupy.  That’s not a partisan view—Senator Wyden is probably Big Tech’s greatest ally in Congress, and I unequivocally called him a liar with regard to the CASE Act—it’s the view of someone who, like many Americans, is weary of policy discussions in which outright bullshit is given equal weight to evidence-based theory and practice.  And with respect to Reed Hunt’s observation, this was an inevitable consequence of giving every citizen a megaphone; but platform immunity like Section 230 is the reason Zuckerberg will call outright bullshit like Holocaust denial an “opinion.”