• Spring naar de hoofdnavigatie
  • Door naar de hoofd inhoud
  • Spring naar de eerste sidebar
  • Spring naar de voettekst

Mediareport

Juridisch weblog voor de media

  • Home
  • Onderwerpen
    • Persrecht
    • Reclamerecht
    • Internetrecht
    • Mediaregulering
    • Entertainment
    • Intellectuele Eigendom
    • Auteursrecht
    • Kansspelen
    • Bestuursrecht
  • Informatie
    • Nieuwsbrief
  • Nederlands
    • English
Home » archief » Is Russmedia really the safe harbour killer?

Is Russmedia really the safe harbour killer?

9 december 2025 door Jens van den Brink

Summary and takeaway

The recent CJEU Russmedia judgment sent shockwaves through the online world. The Court found that an online marketplace is a controller of the personal data contained in an ad placed on its platform by a user. Consequently, before publication, the marketplace has the far-reaching obligation to verify whether the user placing the ad is actually the person whose sensitive data appear in it, or has consented. If that cannot be determined, the ad must be refused. Further, the marketplace ‘must endeavour’ – through ‘appropriate technical and organisational security measures’ – to prevent ads with sensitive data from being copied to other websites.

The ruling could have far reaching consequences. Perhaps not just for online marketplaces providing ads with sensitive data, as the interpretation of the GDPR may be applicable in other situations too. It has implications for anonymous online speech (which will be cheered by many perhaps) and the status of, and liability of, intermediaries, who are unaware of the content they control.

Is this the safe harbour killer? And does the judgment make it near impossible for online intermediaries (not just online marketplaces) to exist? What makes the judgment extra hard to swallow, is the fact the Court seems to pay no regard to the interest of free speech and it deviates from the much more nuanced approach of its advocate general. The decision takes an almost absolutist GDPR stance, which may not promote the interest of data protection, but rather lead to an aversion towards the GDPR.

However, the impact of Russmedia may prove limited (as will be explained in more detail below). The case was decided on the basis of the liability for intermediaries under the e-Commerce Directive. Those provisions have since been replaced by the DSA. Central in the Russmedia judgment are the collision provisions in both the GDPR and the e-Commerce Directive. As a) this provision in the DSA differs substantially from the one in the e-Commerce Directive, b) the DSA is a regulation and not a directive and c) the DSA does not – while the e-Commerce Directive does – determine that it does not apply to certain questions covered by the GDPR, the Russmedia judgment may already be obsolete for legal questions popping up now.

A similar case in the DSA era may very well have a different outcome. Though it will certainly have a major impact, Russmedia may not be the gamechanger it is made out to be.

The facts – Bad cases make bad law?

The judgment may be an example of bad cases making bad law.

The Romanian company Russmedia operates the online marketplace www.publi24.ro, where users can publish advertisements. One of the ad categories is ‘matrimonies’, which seems a euphemism for a collection of sex ads. An anonymous advertiser placed an ad in this category, falsely claiming to offer sexual services by a woman, with her photographs and telephone number, without her knowing or consenting. After Russmedia was notified, the ad was removed within an hour. Textbook notice and takedown. Or was it?

The woman went to court, ending up in Luxembourg, invoking the GDPR and claiming the invasion of privacy was irreparable as the ad had been copied on other websites.

In its press release, the CJEU summarizes that “the operator of an online marketplace such as Russmedia is a controller, within the meaning of the GDPR, of the personal data contained in an advertisement published on its online marketplace. Even if the advertisement is placed by a user, it is published on the internet and thus made accessible to internet users only as a result of the online marketplace.

Consequently, the operator of an online marketplace must, before publication of those advertisements and by means of appropriate technical and organisational measures, identify advertisements that contain sensitive data, such as the data at issue in the present case, and verify whether the user preparing to place such an advertisement is the person whose sensitive data appear in it.

If that is not the case, the operator must verify whether the person whose data are being published has given his or her explicit consent to publication. In the absence of that consent, the operator of an online market place must refuse publication of the advertisement in question, unless it is covered by one of the other exceptions provided for by the GDPR. Furthermore, the operator of an online marketplace must endeavour to prevent advertisements containing sensitive data which are published on its website from being copied and unlawfully published on other websites. To that end, it must implement appropriate technical and organisational security measures.”

GDPR trumps safe harbour?

The  Court assessed the relationship between the interests of data protection under the GDPR and the interest of safe harbour under articles 12-15 of the e-Commerce Directive, which aims to protect intermediary service providers from liability for content placed on their services by third parties. These two interests collided here. The Court pointed to article 1(5)(b) of the e-Commerce Directive, which states that the directive does not apply to questions relating to information society services covered by Directives 95/46 and 97/66 (the GDPR predecessor).

The Court then concludes that safe harbour cannot interfere with the GDPR regime. It finds further confirmation in Article 2(4) of the GDPR, which provides that that regulation is to be ‘without prejudice’ to the application of the e-Commerce Directive, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that directive. This ‘must be understood as meaning that the fact that an operator has obligations laid down by the GDPR does not automatically preclude that operator from being able to rely on Articles 12 to 15 of Directive 2000/31 for matters other than those relating to the protection of personal data’.

According to the CJEU, it follows from a combined reading of these Articles that the provisions of the e-Commerce directive, in particular Articles 12 to 15 thereof, must not interfere with the regime under the GDPR.

That’s pretty clear language from the CJEU. However, this pertains to the collision between the GDPR and the now defunct (at least when it comes to safe harbour) e-Commerce Directive. To determine what the outcome would be of a collision between data protection and safe harbour under current law, depends on the relevant text in the DSA.

The recitals of the DSA determine that the protection of individuals with regard to the processing of personal data is governed solely by the GDPR. However, it is unclear whether that excludes safe harbour. And the real collision clause is in Article 2 (4) of the DSA. And that provision is not the same as the one in the old e-Commerce Directive. It is actually almost identical to the one in the GDPR. Both determine they are ‘without prejudice’ to the rules of the other. That makes it complicated to determine what happens when the two collide. It could therefore be questioned how relevant the Russmedia judgment really is in the DSA era. It will of course be up to the CJEU to determine how this will work out.

Though Russmedia may still have a far-reaching effect, e.g. on determining who is the data controller, or on anonymous online speech, a similar CJEU case under the DSA may very well lead to a very different outcome.

XFacebookLinkedInWhatsAppMessengerEmail

Onderwerp: Entertainment, Internetrecht, Mediaregulering, Persrecht, Privacyrecht Tags: anonymous speech, controller, DSA, GDPR, online marketplace, Russmedia, Safe Harbor, safe harbour

Primaire Sidebar

Zoek

Geschreven door

Jens van den Brink

Tel: +31 20 5506 843
E-mail: jens.van.den.brink@kvdl.com
Bekijk profiel

Lees alle artikelen van deze auteur

Joran Spauwen

Tel: +31 20 5506 625
E-mail: joran.spauwen@kvdl.com
Bekijk profiel

Lees alle artikelen van deze auteur

Inschrijven nieuwsbrief

Meld je nu aan voor de Media Report Nieuwsbrief!

Abonneer

Onderwerpen

  • Persrecht
  • Reclamerecht
  • Internetrecht
  • Mediaregulering
  • Entertainment
  • Intellectuele Eigendom
  • Auteursrecht
  • Kansspelen
  • Bestuursrecht

Footer

Inschrijven nieuwsbrief

Meld je nu aan voor de Media Report Nieuwsbrief!

Abonneer

Copyright © 2026 Media Report