Part 3 · Chapter 25

Internet Safe Harbors From Claims of Copyright Infringement

22,294 words · PDF, page 896

The Origins of the Section 512 Safe Harbors

Originally published in 93 Notre Dame Law Review 499 (2017), adapted with permission.

The DMCA was intended to shepherd copyright into the digital age, but it was drafted at a time when the full implications of digitization and the global interconnectedness of the Internet could not have been fully anticipated. In 1998, only forty-one percent of American households were connected to the Internet, and an hour of television would take more than twenty-four hours to download, assuming you had the latest 56k modem. Google was founded on September 4, 1998, less than two months before the DMCA was signed into law.

The DMCA’s origin story begins in 1993 when President Clinton formed the Information Infrastructure Task Force to articulate and implement the Administration’s vision for the National Information Infrastructure (i.e., the internet). The resulting White Paper was released in 1995 and eventually—after much lobbying, negotiation, forum shopping, and horse trading—morphed into the DMCA that we have today. Note that the White Paper’s legislative proposal contained no relief whatsoever for online intermediaries with respect to infringing user conduct.

The final text adopted in 1998 reflects a compromise between competing interests: Congress wanted to protect copyright owners from the prospect of massive digital piracy, but at the same time it sought to ensure quick access to movies, music, software, and literary works via the internet. Congress did not foresee user-generated content, Facebook posts, tweets, Vines (which used to be a thing), Snapchat videos, and the like; what it had in mind was a kind of “Celestial Jukebox,” which would broadcast traditional content, made by traditional producers, on demand and via subscription.

In the 1990s, traditional commercial copyright producers, such as movie studios, record labels, songwriters, publishing houses, and software companies, were understandably concerned that rapidly spreading digital networks would facilitate the unauthorized copying of perfect digital reproductions of their works on a scale never before seen. Because the Internet promised the dissemination of copyrighted works almost instantaneously, copyright owners were reluctant to make their works available in digital form or online without enhanced legal protection.

On the flip side, the telecommunications providers that connected users to the Internet were concerned that they would be made liable for the infringing conduct of their users--conduct over which they had no real control. This liability could be direct or indirect. Cases in the 1990s, such as Playboy Enterprises, Inc. v. Frena 839 F. Supp. 1552 (M.D. Fla. 1993) and Playboy Enterprises, Inc. v. Russ Hardenburgh, Inc. 982 F. Supp. 503 (N.D. Ohio 1997) suggested that online service providers, such as internet bulletin boards, would be held directly liable for unlawful material posted by their users. However, other cases, such as Religious Technology Center v. Netcom On-Line Communication Services, Inc. 907 F. Supp. 1361 (N.D. Cal. 1995) and CoStar Group, Inc. v. LoopNet, Inc. 373 F.3d 544, 550 (4th Cir. 2004), persuasively reached the opposite conclusion. In Netcom, the district court held that the defendant Internet service provider was not liable for the automatic reproduction of a copyrighted work by its computer system. The court refused to impose direct liability on the service provider, reasoning that “[a]lthough copyright is a strict liability statute, there should still be some element of volition or causation which is lacking where a defendant’s system is merely used to create a copy by a third party.” In CoStar, the Fourth Circuit likewise explained that direct copyright infringement required more than “mere ownership of a machine used by others to make illegal copies.”

Even if it had been clear that courts would adopt the “volitional copy” doctrine from Netcom—as many subsequently have—service providers would still have faced the possibility of indirect liability under copyright law principles of contributory and vicarious liability. Under the principle of contributory copyright infringement, a service provider could be held responsible for user infringement if it had knowledge of, and made a material contribution to, a user’s infringement. Under the principle of vicarious liability, a service provider that had the right and ability to supervise infringing conduct and a direct financial interest in the infringing activity would also be liable. In the Sony Betamax case in 1984, the Supreme Court held that the knowledge required for contributory copyright liability could be established by the sale of an item whose only practical use was to infringe copyright. The corollary of this position was that a manufacturer would not be liable for the infringing acts of end users if the technology in question was a product “widely used for legitimate, unobjectionable purposes. Indeed, it need merely be capable of substantial noninfringing uses.” Nonetheless, subsequent cases have clarified that the fact that a service has a substantial noninfringing use will not shield the service provider if it has actual knowledge of infringement, (Napster) nor if it makes the service available “with the object of promoting its use to infringe copyright, as shown by clear expression or other affirmative steps taken to foster infringement.” (MGM v Grokster)

In the 1990s, copyright’s doctrines of secondary liability were seen as theoretically muddled and somewhat arbitrary in application. Accordingly, service providers had no way of predicting whether courts would apply key concepts, such as “knowledge,” “material contribution,” “the right and ability to supervise,” “financial interest in the infringing activity,” and “substantial noninfringing use” in a way that made them liable. Indeed, whether an Internet service provider that connects households to the Internet, such as Comcast or AT&T, could ever be held liable for the unauthorized transmission and/or storage of copyrighted material without their knowledge remains an open question even today. Likewise, the circumstances under which an online service provider, such as YouTube (a popular video-sharing website) or Flickr (a popular photo-sharing website), could actually be held liable for any infringing uploads by their users is unclear. In the mid-1990s, the issues were sufficiently in doubt that telecommunications providers and would-be providers of other online services convinced Congress that they were reluctant to “make the necessary investment in the expansion of the speed and capacity of the Internet” without reasonable assurances of limited liability for copyright infringement. See Senate Report No. 105-190, at 8 (1998).

Although the Clinton administration initially focused on the reforms that Hollywood was demanding, principally anticircumvention rules now found in section 1201 of the Copyright Act, telecom companies and fledgling ISPs demanded and eventually received safe harbor protection as a quid pro quo. Eventually, Congress enacted a patchwork of reforms, concessions, and incentives tailored to the interests of the major participants. Traditional commercial copyright producers obtained a number of important concessions in exchange for the safe harbors, most notably anticircumvention rules.

Congress sought to preserve “strong incentives for service providers and copyright owners to cooperate” in dealing with online infringement. It also sought to provide “greater certainty to service providers concerning their legal exposure for infringements that may occur in the course of their activities.” To achieve this balance, Internet and online service providers were given significant relief from prospective copyright liability under a set of provisions that are conventionally known as the DMCA safe harbors. Title II of the DMCA, also known as the Online Copyright Infringement Liability Limitation Act, now forms section 512 of the Copyright Act. As the term “safe harbor” suggests, Title II of the DMCA was intended to offer legal certainty to Internet service providers and online platforms if their conduct stayed within certain parameters. Title II was modeled, in part, on the district court decision in Netcom, which held that a service operating automatically at the direction of a user lacks the volitional element required for copyright infringement. But rather than confirming this view of the law, Congress left this and related questions open. That the direct and indirect liability of Internet and online service providers remains open to debate some twenty years later is a testament to the success to the safe harbor regime.

The DMCA safe harbors have been a tremendous benefit to the U.S. copyright system and to the U.S. economy. Together with the protection that Section 230 of the Communications Decency Act provides against state law claims, such as defamation, the Internet safe harbors have propelled the growth of social networking and other “Web 2.0” businesses. Some argue that the safe harbors give too much cover to online intermediaries and diminish their incentives to address online infringement.

Notes and questions

(1) What were the two main compromises that Congress attempted to balance when creating the Section 512 safe harbor provisions?

(2) What specific concern did traditional copyright producers have about the internet in the 1990s, and how did this influence the DMCA’s development?

(3) What does the author mean by stating that ISPs would be “made liable for the infringing conduct of their users—conduct that they could not prevent”? Why was this considered problematic?

(4) For more, see Pamela Samuelson, The U.S. Digital Agenda at WIPO, 37 Virginia Journal of International Law 369 (1997); Jessica Litman, Digital Copyright 89-150 (2001); Timothy Wu, Copyright’s Communications Policy, 103 Michigan Law Review 278, 350-56 (2004); Edward Lee, Decoding the DMCA Safe Harbors, 32 Columbia Journal of Law & the Arts 233 (2009); Annemarie Bridy, Graduated Response and the Turn to Private Ordering in Online Copyright Enforcement, 89 Oregon Law Review 81 (2010); Eric Goldman, How the DMCA’s Online Copyright Safe Harbor Failed, 3 National Taiwan University of Technology Journal of Intellectual Property Law & Management 195 (2014).

The Section 512 Safe Harbors

Overview

There are four DMCA safe harbor provisions located in Section 512 of the Copyright Act. The safe harbors do not change the underlying law of copyright, and they do not impose any affirmative obligation on qualifying service providers. The safe harbors allow qualifying service providers to limit their liability for claims of copyright infringement based on (a) “transitory digital network communications,” (b) “system caching,” (c) “information residing on systems or networks at [the] direction of users,” and (d) “information location tools.”

Service Provider

To qualify for protection under any of the safe harbors, a party must be a “service provider,” as that term is defined in Section 512(k)(1).

17 US Code §512 (k) Definitions.—

(1) Service provider.—

(A) As used in subsection (a), the term “service provider” means an entity offering the transmission, routing, or providing of connections for digital online communications, between or among points specified by a user, of material of the user’s choosing, without modification to the content of the material as sent or received.

(B) As used in this section, other than subsection (a), the term “service provider” means a provider of online services or network access, or the operator of facilities therefor, and includes an entity described in subparagraph (A).

Note that service provider is defined differently for the “transitory digital network communications” safe harbor in subsection (a) than for the remaining three safe harbors. Generally, “service provider” means a provider of online services or network access and includes companies like Comcast that provide Internet connections as well as companies like Facebook and Google that provide services over the Internet.

Conditions for Eligibility–In General

Section 512, subsection (i) specifies certain conditions of eligibility including the adoption and reasonable implementation of a “repeat infringer” policy and the accommodation of the “standard technical measures” used by copyright owners to identify or protect copyrighted works.

17 US Code § 512 (i) Conditions for Eligibility.—

(1) Accommodation of technology.— The limitations on liability established by this section shall apply to a service provider only if the service provider—

(A) has adopted and reasonably implemented, and informs subscribers and account holders of the service provider’s system or network of, a policy that provides for the termination in appropriate circumstances of subscribers and account holders of the service provider’s system or network who are repeat infringers; and

(B) accommodates and does not interfere with standard technical measures.

(2) Definition.— As used in this subsection, the term “standard technical measures” means technical measures that are used by copyright owners to identify or protect copyrighted works and—

(A) have been developed pursuant to a broad consensus of copyright owners and service providers in an open, fair, voluntary, multi-industry standards process;

(B) are available to any person on reasonable and nondiscriminatory terms; and

(C) do not impose substantial costs on service providers or substantial burdens on their systems or networks.

Note that each particular safe harbor has its own additional requirements.

Conditions for eligibility–repeat infringer policies

The safe harbor conditions of eligibility require that service providers adopt and reasonably implement a policy for terminating the accounts of repeat infringers. See Section 512(i)(1)(A) extracted above.

Although Section 512(i)(1)(A) prescribes no particular form for a repeat-infringer policy, there are at least two foundational requirements. At minimum, a service provider must (a) independently maintain records of infringing activity, including activity identified through takedown notices, that it links to responsible subscribers; and (b) have an account termination process linked to infringement so identified. See, e.g., Capitol Records, LLC v. Escape Media Grp., Inc., 2015 WL 1402049, at *5-6 (S.D.N.Y. Mar. 25, 2015). A service provider that does not use takedown notices to identify infringing users has not “reasonably implemented” a repeat-infringer policy.

As the district court in Capitol Records, Inc. v. MP3tunes, LLC, 821 F.Supp.2d 627, 637 (S.D.N.Y.2011) explained, the requirement that service providers implement a repeat-infringer policy is a “fundamental safeguard for copyright owners” and “essential to maintain the strong incentives for service providers to prevent their services from becoming safe havens or conduits for known repeat copyright infringers.”

This requirement to reasonably implement a repeat infringer policy is an important condition on safe harbor eligibility, but has not been interpreted to be a particularly onerous one. In Capitol Records, LLC v. Vimeo, LLC, 972 F. Supp. 2d 500, 513 (S.D.N.Y. 2013), the court indicated that a threshold obligation to adopt a repeat infringer policy “should not be an overly burdensome one to meet.” Courts have not, for example, equated a repeat-infringer policy with a three-strikes policy of graduated response. However, recent litigation by BMG Rights Management has sought to test the boundaries of what it means to reasonably implement a repeat infringer policy.

A case study in how not to implement a repeat infringer policy: BMG Rights Management (US) LLC v. Cox Communications, Inc., 881 F.3d 293 (4th Cir. 2018)

Discovery in BMG v. Cox revealed that prior to September 2012 Cox had an elaborate 13-strike policy leading up to nominal termination and routine reactivation of identified infringers. As one internal email explained, “once the customer has been terminated for DMCA, we have fulfilled the obligation of the DMCA safe harbor and can start over.” Another summarized more succinctly, “DMCA = reactivate.” Until September 2012, Cox never terminated a subscriber for infringement without reactivating them. After September 2012 Cox changed its practice and in the words of an internal email: “we now terminate, for real.” However the record showed that instead of terminating and then reactivating subscribers, Cox simply stopped terminating them in the first place.

In addition, at some point in time, Cox decided to delete automatically all infringement notices received from BMG’s agent, Rightscorp. As a result, Cox received none of the millions of infringement notices that Rightscorp sent to Cox on BMG’s behalf during the relevant period. The court of appeals took a dim view of this, “Cox’s decision to categorically disregard all notices from Rightscorp provides further evidence that Cox did not reasonably implement a repeat infringer policy.” Finally, the plaintiff was able to point to particular instances where Cox employees had identified a subscriber as a repeat infringer and yet failed to terminate. Cox might have had more success in minimizing isolated instances of failure were it not for internal emails directing an employee not to terminate an infringer and explicitly noting the access provider’s financial incentive not to terminate. Remarkably, Cox was unable to produce any evidence of instances in which it did follow through on its policy and terminate subscribers after giving them a final warning to stop infringing.

The court of appeals agreed with the district court’s grim assessment:

Here, Cox formally adopted a repeat infringer “policy,” but, both before and after September 2012, made every effort to avoid reasonably implementing that policy. Indeed, in carrying out its thirteen-strike process, Cox very clearly determined not to terminate subscribers who in fact repeatedly violated the policy.

The court of appeals concluded:

Cox failed to qualify for the DMCA safe harbor because it failed to implement its policy in any consistent or meaningful way—leaving it essentially with no policy.

The Cox case raises more questions than it answers. To begin with, under Cox’s policy, it never seemed to actually terminate any subscribers. The court of appeals indicates that a repeat infringer policy must trigger termination at some stage. However, the court of appeals does not actually address the adequacy of Cox’s thirteen-strike policy if it had resulted in termination.

Cox’s system escalated from no action for the first notice of infringement through a series of warning emails, suspensions with reactivation after a verbal warning delivered by a technician. At the 13th notice “the subscriber is again suspended, and, for the first time, considered for termination.” As well as being gradual, Cox’s policy restricted the number of notices it would process from any copyright holder or agent in one day; it only counted one notice per subscriber per day; and it reset each subscriber’s thirteen-strike counter every six months.

How should such policies be judged? The Court of Appeals in BMG v. Cox did not elaborate on criteria to assess a repeat infringer policy, but it did make a passing reference to the “effectiveness of Cox’s thirteen-strike policy as a deterrent to copyright infringement.” Should policies be judged on their effectiveness at deterring copyright infringement?

Courts have been reluctant to be too prescriptive about repeat infringer policies, nor are they likely to insist that policies be followed perfectly in every case. As the court of appeals in BMG v. Cox explained:

We are mindful of the need to afford ISPs flexibility in crafting repeat infringer policies, and of the difficulty of determining when it is “appropriate” to terminate a person’s access to the Internet. At a minimum, however, an ISP has not “reasonably implemented” a repeat infringer policy if the ISP fails to enforce the terms of its policy in any meaningful fashion.

Was the problem with Cox’s policy that it was too lenient, or too discretionary, or both?

Rightscorp, Inc., was hired by the plaintiffs to assist with copyright enforcement and it was not a party in BMG v. Cox (although it was represented by the same law firm), but it played a significant role in the case. Indeed the defendant’s refusal to pass along Rightscorp’s infringement notices to its subscribers was probably what precipitated the litigation. As the court of appeals explained,

Rightscorp also asks the ISP to forward the notice to the allegedly infringing subscriber, since only the ISP can match the IP address to the subscriber’s identity. For that purpose, the notice contains a settlement offer, allowing the alleged infringer to pay twenty or thirty dollars for a release from liability for the instance of infringement alleged in the notice. Cox has determined to refuse to forward or process notices that contain such settlement language. When Cox began receiving Rightscorp notices in the spring of 2011 (before Rightscorp had signed BMG as a client), Cox notified Rightscorp that it would process the notices only if Rightscorp removed the settlement language. Rightscorp did not do so. Cox never considered removing the settlement language itself or using other means to inform its subscribers of the allegedly infringing activity observed by Rightscorp.

Rightscorp’s settlement offers can pose a trap for the unwary. A subscriber who accepts Rightscorp’s offer for any single work is giving Rightscorp a vital piece of information, their identity. Once Rightscorp had made the link between the subscriber and their IP address for one work, it can then demand much larger settlements for other works the subscriber (or someone using their IP address) is believed to have infringed.

There is little substantive discussion in the Cox case of how Rightscorp identifies instances of infringement, how reliable their process is, whether their demands to convey their settlement offers are reasonable, or whether merely refusing such a demand takes the ISP outside the scope of the safe harbors. In Defense Against the Dark Arts of Copyright Trolling, 103 Iowa Law Review 571 (2018), Matthew Sag and Jake Haskell argue that copyright litigation relating to alleged uses of the file sharing system BitTorrent has “victimized a substantial number of non-infringers” and they contend that “this seems to be a feature of the plaintiffs’ business model, not a bug.” They also argue that “although it would not be particularly difficult to amass credible and reliable evidence of online infringement over peer-to-peer networks, the plaintiffs [in the BitTorrent cases] do not appear to have done so.” Sag and Haskell were not discussing Rightscorp, but that company’s technology is similar to the classic copyright trolls at work in cases involving the disgraced Prenda law firm and the pornography company, Malibu Media. Should the concerns Sag and Haskell raise give the courts second thoughts about requiring ISPs to take Rightscorp infringement notifications on faith? Would an ISP ever be justified in blacklisting an entity like Rightscorp?

The end of the Cox litigation

The story that begins with the Fourth Circuit’s 2018 safe harbor ruling ends at the Supreme Court. After the safe harbor was lost, the case went to trial on the underlying secondary liability claims and produced a billion-dollar verdict against Cox. In Cox Communications, Inc. v. Sony Music Entertainment, 146 S. Ct. 959 (2026), the Supreme Court reversed. The full decision is discussed in the chapter on secondary liability. For present purposes, it is enough to note that Sony argued that the safe harbor would have no work to do if an internet service provider could not be held liable for continuing to serve known infringers. After all, Section 512(i)(1)(A) conditions the safe harbor on terminating repeat infringers “in appropriate circumstances,” and so Congress must have legislated against the background assumption that failing to terminate them creates exposure.

Justice Thomas responded that “Sony overreads the DMCA”: the statute confers immunity, and a provision conferring immunity does not silently create the liability it protects against. Justice Sotomayor, concurring in the judgment and joined by Justice Jackson, saw things differently and expressed concern that if a provider incurs no liability for keeping known infringers connected, the incentive to run a meaningful repeat infringer policy disappears. The majority did not appear troubled by this. One way to read Justice Thomas’s opinion is that it is not really about the DMCA at all. It begins from the premise that secondary liability in copyright should track secondary liability everywhere else in civil law, rather than being stretched to accommodate the particular structure Congress built for online intermediaries. On that premise, the Court had no reason to distort the ordinary meaning of contributory infringement in order to preserve a separation between common law liability and the statutory safe harbors that Congress never actually wrote into the statute.

Cox has already begun to reshape the surrounding litigation. In Grande Communications Networks, LLC v. UMG Recordings, Inc., 146 S. Ct. 2152 (2026), the Supreme Court granted certiorari, vacated the Fifth Circuit’s judgment, and remanded for reconsideration in light of Cox.

Who is a repeat infringer?

The court of appeals in BMG v. Cox rejected the argument that the term “repeat infringers” in § 512(i) applied only to that “narrow subset of those who have been so adjudicated by a court.” (at 301). The court held instead that “use the term ‘infringer’ (and similar terms) to refer[s] to all who engage in infringing activity.” But notice that the court does not say how credible or precise an allegation of infringement must be to fall within an ISP’s repeat infringer policy. Some questions that the court leaves unanswered in BMG v. Cox include:

  • What if an ISP had reason to doubt the accuracy of the infringement allegation?

  • Would an ISP “reasonably implement” a repeat infringer policy if it set minimum requirements to ensure that accusations of infringement were accurate?

  • What if a notifying entity like Rightscorp insisted on using a form of notice that made it difficult or expensive for an ISP to keep up with a large volume of notifications?

  • Would an ISP “reasonably implement” a repeat infringer policy if it required notices (other than DMCA takedown notices) to be delivered in a particular format, subject to particular authentications, etc.?

Cox and BMG settled in 2018, but Cox faced a similar lawsuit from Sony that eventually resulted in a billion-dollar verdict and a decision of the Supreme Court, discussed at the end of this chapter.

For an extended discussion on Section 512(i)(A) and what it means to reasonably implement a repeat infringer policy, click here.

Section 512(c) “storage at the direction of a user”

The statute

The most litigated of the DMCA safe harbors is Section 512(c) which covers infringement claims that arise “by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider.”

17 US Code § 512 (c) Information Residing on Systems or Networks At Direction of Users.—

(1) In general.— A service provider shall not be liable for monetary relief, or, except as provided in subsection (j), for injunctive or other equitable relief, for infringement of copyright by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider, if the service provider—

(A)

(i) does not have actual knowledge that the material or an activity using the material on the system or network is infringing;

(ii) in the absence of such actual knowledge, is not aware of facts or circumstances from which infringing activity is apparent; or

(iii) upon obtaining such knowledge or awareness, acts expeditiously to remove, or disable access to, the material;

(B) does not receive a financial benefit directly attributable to the infringing activity, in a case in which the service provider has the right and ability to control such activity; and

(C) upon notification of claimed infringement as described in paragraph (3), responds expeditiously to remove, or disable access to, the material that is claimed to be infringing or to be the subject of infringing activity.

Section 512(c) has two further subsections. Subsection (2) sets out the requirement for a designated agent to receive notices of infringement. Subsection (3) sets out the requirements for an effective notification for the “notice and takedown” regime envisaged by the safe harbor.

What counts as knowledge of infringement under the DMCA safe harbors?

The most significant safe harbor requirement in the DMCA is that platforms must avoid knowledge of specific and identifiable instances of copyright infringement by their users—i.e., they must maintain plausible deniability.

For a service provider such as an Internet platform to remain eligible for the User Directed Content or Information Location Tools safe harbors it must avoid both actual knowledge and red flag knowledge of specific acts of infringement. See Sections 512(c)(1)(A)(i)–(ii), (d)(1)(A)–(B). The relevant provisions for both safe harbors provide that the service provider must “not have actual knowledge that the material or an activity using the material on the system or network is infringing”; or “in the absence of such actual knowledge,” it must not be “aware of facts or circumstances from which infringing activity is apparent.” If either of these knowledge thresholds are triggered, the service provider must “upon obtaining such knowledge or awareness, act[ ] expeditiously to remove, or disable access to, the material.” See § 512(c)(1)(A)(iii).

Viacom International, Inc. v. YouTube, Inc., 676 F.3d 19 (2d Cir. 2012)

JOSÉ A. CABRANES, Circuit Judge:

This appeal requires us to clarify the contours of the “safe harbor” provision of the Digital Millennium Copyright Act (DMCA) that limits the liability of online service providers for copyright infringement that occurs “by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider.” 17 U.S.C. § 512(c).

The plaintiffs-appellants in these related actions appeal from an August 10, 2010 judgment of the United States District Court for the Southern District of New York (Louis L. Stanton, Judge), which granted summary judgment to defendants-appellees YouTube, Inc., YouTube, LLC, and Google Inc. The plaintiffs alleged direct and secondary copyright infringement based on the public performance, display, and reproduction of approximately 79,000 audiovisual “clips” that appeared on the YouTube website between 2005 and 2008.

BACKGROUND

A. The DMCA Safe Harbors

The DMCA was enacted in 1998 to implement the World Intellectual Property Organization Copyright Treaty, and to update domestic copyright law for the digital age. Title II of the DMCA, separately titled the “Online Copyright Infringement Liability Limitation Act” (OCILLA), was designed to “clarify the liability faced by service providers who transmit potentially infringing material over their networks.” S.Rep. No. 105-190 at 2 (1998). But “rather than embarking upon a wholesale clarification” of various copyright doctrines, Congress elected “to leave current law in its evolving state and, instead, to create a series of ‘safe harbors[]’ for certain common activities of service providers.” Id. at 19. To that end, OCILLA established a series of four “safe harbors” that allow qualifying service providers to limit their liability for claims of copyright infringement based on (a) “transitory digital network communications,” (b) “system caching,” (c) “information residing on systems or networks at [the] direction of users,” and (d) “information location tools.” 17 U.S.C. § 512(a)-(d).

To qualify for protection under any of the safe harbors, a party must meet a set of threshold criteria. First, the party must in fact be a “service provider,” defined, in pertinent part, as “a provider of online services or network access, or the operator of facilities therefor.” 17 U.S.C. § 512(k)(1)(B). A party that qualifies as a service provider must also satisfy certain “conditions of eligibility,” including the adoption and reasonable implementation of a “repeat infringer” policy that “provides for the termination in appropriate circumstances of subscribers and account holders of the service provider’s system or network.” Id. § 512(i)(1)(A). In addition, a qualifying service provider must accommodate “standard technical measures” that are “used by copyright owners to identify or protect copyrighted works.” Id. § 512(i)(1)(B), (i)(2).

Beyond the threshold criteria, a service provider must satisfy the requirements of a particular safe harbor. In this case, the safe harbor at issue is § 512(c), which covers infringement claims that arise “by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider.” Id. § 512(c)(1). The § 512(c) safe harbor will apply only if the service provider:

(A) (i) does not have actual knowledge that the material or an activity using the material on the system or network is infringing;

(ii) in the absence of such actual knowledge, is not aware of facts or circumstances from which infringing activity is apparent; or

(iii) upon obtaining such knowledge or awareness, acts expeditiously to remove, or disable access to, the material;

(B) does not receive a financial benefit directly attributable to the infringing activity, in a case in which the service provider has the right and ability to control such activity; and

(C) upon notification of claimed infringement as described in paragraph (3), responds expeditiously to remove, or disable access to, the material that is claimed to be infringing or to be the subject of infringing activity.

Id. § 512(c)(1)(A)-(C). Section 512(c) also sets forth a detailed notification scheme that requires service providers to “designate[] an agent to receive notifications of claimed infringement,” id. § 512(c)(2), and specifies the components of a proper notification, commonly known as a “takedown notice,” to that agent, see id. § 512(c)(3). Thus, actual knowledge of infringing material, awareness of facts or circumstances that make infringing activity apparent, or receipt of a takedown notice will each trigger an obligation to expeditiously remove the infringing material.

With the statutory context in mind, we now turn to the facts of this case.

B. Factual Background

YouTube was founded in February 2005 by Chad Hurley, Steve Chen, and Jawed Karim, three former employees of the internet company Paypal. When YouTube announced the “official launch” of the website in December 2005, a press release described YouTube as a “consumer media company” that “allows people to watch, upload, and share personal video clips at www.YouTube.com.” Under the slogan “Broadcast yourself,” YouTube achieved rapid prominence and profitability, eclipsing competitors such as Google Video and Yahoo Video by wide margins. In November 2006, Google acquired YouTube in a stock-for-stock transaction valued at $1.65 billion. By March 2010, at the time of summary judgment briefing in this litigation, site traffic on YouTube had soared to more than 1 billion daily video views, with more than 24 hours of new video uploaded to the site every minute.

The basic function of the YouTube website permits users to “upload” and view video clips free of charge. Before uploading a video to YouTube, a user must register and create an account with the website. The registration process requires the user to accept YouTube’s Terms of Use agreement, which provides, inter alia, that the user “will not submit material that is copyrighted... unless [he is] the owner of such rights or ha[s] permission from their rightful owner to post the material and to grant YouTube all of the license rights granted herein.” When the registration process is complete, the user can sign in to his account, select a video to upload from the user’s personal computer, mobile phone, or other device, and instruct the YouTube system to upload the video by clicking on a virtual upload “button.”

Uploading a video to the YouTube website triggers a series of automated software functions. During the upload process, YouTube makes one or more exact copies of the video in its original file format. YouTube also makes one or more additional copies of the video in “Flash” format, a process known as “transcoding.” The transcoding process ensures that YouTube videos are available for viewing by most users at their request. The YouTube system allows users to gain access to video content by “streaming” the video to the user’s computer in response to a playback request. YouTube uses a computer algorithm to identify clips that are “related” to a video the user watches and display links to the “related” clips.

C. Procedural History

Plaintiff Viacom, an American media conglomerate, and various Viacom affiliates filed suit against YouTube on March 13, 2007, alleging direct and secondary copyright infringement based on the public performance, display, and reproduction of their audiovisual works on the YouTube website. Plaintiff Premier League, an English soccer league, and Plaintiff Bourne Co. filed a putative class action against YouTube on May 4, 2007, alleging direct and secondary copyright infringement on behalf of all copyright owners whose material was copied, stored, displayed, or performed on YouTube without authorization. Specifically at issue were some 63,497 video clips identified by Viacom, as well as 13,500 additional clips (jointly, the “clips-in-suit”) identified by the putative class plaintiffs.

At the close of discovery, the parties in both actions cross-moved for partial summary judgment with respect to the applicability of the DMCA safe harbor defense. The District Court denied the plaintiffs’ motions and granted summary judgment to the defendants, finding that YouTube qualified for DMCA safe harbor protection with respect to all claims of direct and secondary copyright infringement. The District Court prefaced its analysis of the DMCA safe harbor by holding that, based on the plaintiffs’ summary judgment submissions, “a jury could find that the defendants not only were generally aware of, but welcomed, copyright-infringing material being placed on their website.” However, the District Court also noted that the defendants had properly designated an agent pursuant to § 512(c)(2), and “when they received specific notice that a particular item infringed a copyright, they swiftly removed it.” Accordingly, the District Court identified the crux of the inquiry with respect to YouTube’s copyright liability as follows:

[T]he critical question is whether the statutory phrases “actual knowledge that the material or an activity using the material on the system or network is infringing,” and “facts or circumstances from which infringing activity is apparent” in § 512(c)(1)(A)(i) and (ii) mean a general awareness that there are infringements (here, claimed to be widespread and common), or rather mean actual or constructive knowledge of specific and identifiable infringements of individual items.

After quoting at length from the legislative history of the DMCA, the District Court held that “the phrases ‘actual knowledge that the material or an activity’ is infringing, and ‘facts or circumstances’ indicating infringing activity, describe knowledge of specific and identifiable infringements of particular individual items.” “Mere knowledge of [the] prevalence of such activity in general,” the District Court concluded, “is not enough.”

In a final section labeled “Other Points,” the District Court rejected two additional claims. First, it rejected the plaintiffs’ argument that the replication, transmittal and display of YouTube videos are functions that fall outside the protection § 512(c)(1) affords for “infringement of copyright by reason of ... storage at the direction of the user.” Second, it rejected the plaintiffs’ argument that YouTube was ineligible for safe harbor protection under the control provision, holding that the “right and ability to control” infringing activity under § 512(c)(1)(B) requires “item-specific” knowledge thereof, because “the provider must know of the particular case before he can control it.”

Following the June 23 Opinion, final judgment in favor of YouTube was entered on August 10, 2010. These appeals followed.

DISCUSSION

We review an order granting summary judgment de novo, drawing all factual inferences in favor of the non-moving party.

A. Actual and “Red Flag” Knowledge: § 512(c)(1)(A)

The first and most important question on appeal is whether the DMCA safe harbor at issue requires “actual knowledge” or “awareness” of facts or circumstances indicating “specific and identifiable infringements,” We consider first the scope of the statutory provision and then its application to the record in this case.

1. The Specificity Requirement

As in all statutory construction cases, we begin with the language of the statute. Under § 512(c)(1)(A), safe harbor protection is available only if the service provider:

(i) does not have actual knowledge that the material or an activity using the material on the system or network is infringing;

(ii) in the absence of such actual knowledge, is not aware of facts or circumstances from which infringing activity is apparent; or

(iii) upon obtaining such knowledge or awareness, acts expeditiously to remove, or disable access to, the material....

17 U.S.C. § 512(c)(1)(A). As previously noted, the District Court held that the statutory phrases “actual knowledge that the material ... is infringing” and “facts or circumstances from which infringing activity is apparent” refer to “knowledge of specific and identifiable infringements.” For the reasons that follow, we substantially affirm that holding.

Although the parties marshal a battery of other arguments on appeal, it is the text of the statute that compels our conclusion. In particular, we are persuaded that the basic operation of § 512(c) requires knowledge or awareness of specific infringing activity. Under § 512(c)(1)(A), knowledge or awareness alone does not disqualify the service provider; rather, the provider that gains knowledge or awareness of infringing activity retains safe-harbor protection if it “acts expeditiously to remove, or disable access to, the material.” 17 U.S.C. § 512(c)(1)(A)(iii). Thus, the nature of the removal obligation itself contemplates knowledge or awareness of specific infringing material, because expeditious removal is possible only if the service provider knows with particularity which items to remove. Indeed, to require expeditious removal in the absence of specific knowledge or awareness would be to mandate an amorphous obligation to “take commercially reasonable steps” in response to a generalized awareness of infringement. Such a view cannot be reconciled with the language of the statute, which requires “expeditious[]” action to remove or disable “the material” at issue. 17 U.S.C. § 512(c)(1)(A)(iii) (emphasis added).

On appeal, the plaintiffs dispute this conclusion by drawing our attention to § 512(c)(1)(A)(ii), the so-called “red flag” knowledge provision. See id. § 512(c)(1)(A)(ii) (limiting liability where, “in the absence of such actual knowledge, [the service provider] is not aware of facts or circumstances from which infringing activity is apparent”). In their view, the use of the phrase “facts or circumstances” demonstrates that Congress did not intend to limit the red flag provision to a particular type of knowledge. The plaintiffs contend that requiring awareness of specific infringements in order to establish “aware[ness] of facts or circumstances from which infringing activity is apparent,” 17 U.S.C. § 512(c)(1)(A)(ii), renders the red flag provision superfluous, because that provision would be satisfied only when the “actual knowledge” provision is also satisfied. For that reason, the plaintiffs urge the Court to hold that the red flag provision “requires less specificity” than the actual knowledge provision.

This argument misconstrues the relationship between “actual” knowledge and “red flag” knowledge. It is true that we are required to disfavor interpretations of statutes that render language superfluous. But contrary to the plaintiffs’ assertions, construing § 512(c)(1)(A) to require actual knowledge or awareness of specific instances of infringement does not render the red flag provision superfluous. The phrase “actual knowledge,” which appears in § 512(c)(1)(A)(i), is frequently used to denote subjective belief. By contrast, courts often invoke the language of “facts or circumstances,” which appears in § 512(c)(1)(A)(ii), in discussing an objective reasonableness standard. See, e.g., Maxwell v. City of New York, 380 F.3d 106, 108 (2d Cir.2004) (“Police officers’ application of force is excessive ... if it is objectively unreasonable in light of the facts and circumstances confronting them, without regard to their underlying intent or motivation.”

The difference between actual and red flag knowledge is thus not between specific and generalized knowledge, but instead between a subjective and an objective standard. In other words, the actual knowledge provision turns on whether the provider actually or “subjectively” knew of specific infringement, while the red flag provision turns on whether the provider was subjectively aware of facts that would have made the specific infringement “objectively” obvious to a reasonable person. The red flag provision, because it incorporates an objective standard, is not swallowed up by the actual knowledge provision under our construction of the § 512(c) safe harbor. Both provisions do independent work, and both apply only to specific instances of infringement.

The limited body of case law interpreting the knowledge provisions of the § 512(c) safe harbor comports with our view of the specificity requirement. [In particular, in UMG Recordings, Inc. v. Shelter Capital Partners LLC (9th Cir. 2011) the Ninth Circuit ruled that Veoh, a video-hosting service, qualified for the DMCA safe harbor. The court rejected a “broad conception” of the knowledge requirement, holding that §512(c) demands specific knowledge of particular infringing activity. The court held that the same standard applied to the “red flag” provision: service providers are not required to determine independently whether material is illegal.]

Based on the text of § 512(c)(1)(A), as well as the limited case law on point, we affirm the District Court’s holding that actual knowledge or awareness of facts or circumstances that indicate specific and identifiable instances of infringement will disqualify a service provider from the safe harbor.

2. The Grant of Summary Judgment

The corollary question on appeal is whether, under the foregoing construction of § 512(c)(1)(A), the District Court erred in granting summary judgment to YouTube on the record presented. For the reasons that follow, we hold that although the District Court correctly interpreted § 512(c)(1)(A), summary judgment for the defendants was premature.

i. Specific Knowledge or Awareness

The plaintiffs argue that, even under the District Court’s construction of the safe harbor, the record raises material issues of fact regarding YouTube’s actual knowledge or “red flag” awareness of specific instances of infringement. To that end, the plaintiffs draw our attention to various estimates regarding the percentage of infringing content on the YouTube website. For example, Viacom cites evidence that YouTube employees conducted website surveys and estimated that 75-80% of all YouTube streams contained copyrighted material. The class plaintiffs similarly claim that Credit Suisse, acting as financial advisor to Google, estimated that more than 60% of YouTube’s content was “premium” copyrighted content — and that only 10% of the premium content was authorized. These approximations suggest that the defendants were conscious that significant quantities of material on the YouTube website were infringing. See Viacom Int’l, 718 F.Supp.2d at 518 (“[A] jury could find that the defendants not only were generally aware of, but welcomed, copyright-infringing material being placed on their website.”). But such estimates are insufficient, standing alone, to create a triable issue of fact as to whether YouTube actually knew, or was aware of facts or circumstances that would indicate, the existence of particular instances of infringement.

Beyond the survey results, the plaintiffs rely upon internal YouTube communications that do refer to particular clips or groups of clips. The class plaintiffs argue that YouTube was aware of specific infringing material because, inter alia, YouTube attempted to search for specific Premier League videos on the site in order to gauge their “value based on video usage.” In particular, the class plaintiffs cite a February 7, 2007 e-mail from Patrick Walker, director of video partnerships for Google and YouTube, requesting that his colleagues calculate the number of daily searches for the terms “soccer,” “football,” and “Premier League” in preparation for a bid on the global rights to Premier League content. On another occasion, Walker requested that any “clearly infringing, official broadcast footage” from a list of top Premier League clubs — including Liverpool Football Club, Chelsea Football Club, Manchester United Football Club, and Arsenal Football Club — be taken down in advance of a meeting with the heads of “several major sports teams and leagues.” YouTube ultimately decided not to make a bid for the Premier League rights — but the infringing content allegedly remained on the website.

The record in the Viacom action includes additional examples. For instance, YouTube founder Jawed Karim prepared a report in March 2006 which stated that, “as of today, episodes and clips of the following well-known shows can still be found [on YouTube]: Family Guy, South Park, MTV Cribs, Daily Show, Reno 911, [and] Dave Chapelle [sic].” Karim further opined that, “although YouTube is not legally required to monitor content ... and complies with DMCA takedown requests, we would benefit from preemptively removing content that is blatantly illegal and likely to attract criticism.” He also noted that “a more thorough analysis” of the issue would be required. At least some of the TV shows to which Karim referred are owned by Viacom. A reasonable juror could conclude from the March 2006 report that Karim knew of the presence of Viacom-owned material on YouTube, since he presumably located specific clips of the shows in question before he could announce that YouTube hosted the content “[a]s of today.” A reasonable juror could also conclude that Karim believed the clips he located to be infringing (since he refers to them as “blatantly illegal”), and that YouTube did not remove the content from the website until conducting “a more thorough analysis,” thus exposing the company to liability in the interim.

Furthermore, in a July 4, 2005 e-mail exchange, YouTube founder Chad Hurley sent an e-mail to his co-founders with the subject line “budlight commercials,” and stated, “we need to reject these too.” Steve Chen responded, “can we please leave these in a bit longer? another week or two can’t hurt.” Karim also replied, indicating that he “added back in all 28 bud videos.” Similarly, in an August 9, 2005 e-mail exchange, Hurley urged his colleagues “to start being diligent about rejecting copyrighted / inappropriate content,” noting that “there is a cnn clip of the shuttle clip on the site today, if the boys from Turner would come to the site, they might be pissed?” Again, Chen resisted:

but we should just keep that stuff on the site. i really don’t see what will happen. what? someone from cnn sees it? he happens to be someone with power? he happens to want to take it down right away. he gets in touch with cnn legal. 2 weeks later, we get a cease & desist letter. we take the video down.

And again, Karim agreed, indicating that “the CNN space shuttle clip, I like. we can remove it once we’re bigger and better known, but for now that clip is fine.”

Upon a review of the record, we are persuaded that the plaintiffs may have raised a material issue of fact regarding YouTube’s knowledge or awareness of specific instances of infringement. The foregoing Premier League e-mails request the identification and removal of “clearly infringing, official broadcast footage.” The March 2006 report indicates Karim’s awareness of specific clips that he perceived to be “blatantly illegal.” Similarly, the Bud Light and space shuttle e-mails refer to particular clips in the context of correspondence about whether to remove infringing material from the website. On these facts, a reasonable juror could conclude that YouTube had actual knowledge of specific infringing activity, or was at least aware of facts or circumstances from which specific infringing activity was apparent. See § 512(c)(1)(A)(i)-(ii). Accordingly, we hold that summary judgment to YouTube on all clips-in-suit, especially in the absence of any detailed examination of the extensive record on summary judgment, was premature.

ii. “Willful Blindness”

The plaintiffs further argue that the District Court erred in granting summary judgment to the defendants despite evidence that YouTube was “willfully blind” to specific infringing activity. On this issue of first impression, we consider the application of the common law willful blindness doctrine in the DMCA context.

The principle that willful blindness is tantamount to knowledge is hardly novel. Tiffany (NJ) Inc. v. eBay, Inc., 600 F.3d 93, 110 n. 16 (2d Cir.2010). A person is “willfully blind” or engages in “conscious avoidance” amounting to knowledge where the person “was aware of a high probability of the fact in dispute and consciously avoided confirming that fact.” United States v. Aina-Marshall, 336 F.3d 167, 170 (2d Cir.2003); cf. Global-Tech Appliances, Inc. v. SEB S.A., 131 S.Ct. 2060 (2011) (applying the willful blindness doctrine in a patent infringement case). Writing in the trademark infringement context, we have held that “[a] service provider is not ... permitted willful blindness. When it has reason to suspect that users of its service are infringing a protected mark, it may not shield itself from learning of the particular infringing transactions by looking the other way.” Tiffany, 600 F.3d at 109.

The DMCA does not mention willful blindness. As a general matter, we interpret a statute to abrogate a common law principle only if the statute speaks directly to the question addressed by the common law. The relevant question, therefore, is whether the DMCA speaks directly to the principle of willful blindness. The DMCA provision most relevant to the abrogation inquiry is § 512(m), which provides that safe harbor protection shall not be conditioned on “a service provider monitoring its service or affirmatively seeking facts indicating infringing activity, except to the extent consistent with a standard technical measure complying with the provisions of subsection (i).” 17 U.S.C. § 512(m)(1). Section 512(m) is explicit: DMCA safe harbor protection cannot be conditioned on affirmative monitoring by a service provider. For that reason, § 512(m) is incompatible with a broad common law duty to monitor or otherwise seek out infringing activity based on general awareness that infringement may be occurring. That fact does not, however, dispose of the abrogation inquiry; as previously noted, willful blindness cannot be defined as an affirmative duty to monitor. See Aina-Marshall, 336 F.3d at 170 (holding that a person is “willfully blind” where he “was aware of a high probability of the fact in dispute and consciously avoided confirming that fact”). Because the statute does not “speak directly” to the willful blindness doctrine, § 512(m) limits — but does not abrogate — the doctrine. Accordingly, we hold that the willful blindness doctrine may be applied, in appropriate circumstances, to demonstrate knowledge or awareness of specific instances of infringement under the DMCA.

The District Court cited § 512(m) for the proposition that safe harbor protection does not require affirmative monitoring, but did not expressly address the principle of willful blindness or its relationship to the DMCA safe harbors. As a result, whether the defendants made a “deliberate effort to avoid guilty knowledge,” remains a fact question for the District Court to consider in the first instance on remand.

B. Control and Benefit: § 512(c)(1)(B)

Apart from the foregoing knowledge provisions, the § 512(c) safe harbor provides that an eligible service provider must “not receive a financial benefit directly attributable to the infringing activity, in a case in which the service provider has the right and ability to control such activity.” 17 U.S.C. § 512(c)(1)(B). The District Court addressed this issue in a single paragraph, quoting from § 512(c)(1)(B), the so-called “control and benefit” provision, and concluding that the right and ability to control the activity requires knowledge of it, which must be item-specific. For the reasons that follow, we hold that the District Court erred by importing a specific knowledge requirement into the control and benefit provision, and we therefore remand for further fact-finding on the issue of control.

1. “Right and Ability to Control” Infringing Activity

On appeal, the parties advocate two competing constructions of the “right and ability to control” infringing activity. 17 U.S.C. § 512(c)(1)(B). Because each is fatally flawed, we reject both proposed constructions in favor of a fact-based inquiry to be conducted in the first instance by the District Court.

The first construction, pressed by the defendants, is the one adopted by the District Court, which held that “the provider must know of the particular case before he can control it.” The trouble with this construction is that importing a specific knowledge requirement into § 512(c)(1)(B) renders the control provision duplicative of § 512(c)(1)(A). Any service provider that has item-specific knowledge of infringing activity and thereby obtains financial benefit would already be excluded from the safe harbor under § 512(c)(1)(A) for having specific knowledge of infringing material and failing to effect expeditious removal. No additional service provider would be excluded by § 512(c)(1)(B) that was not already excluded by § 512(c)(1)(A). Because statutory interpretations that render language superfluous are disfavored, we reject the District Court’s interpretation of the control provision.

The second construction, urged by the plaintiffs, is that the control provision codifies the common law doctrine of vicarious copyright liability. The general rule with respect to common law codification is that when Congress uses terms that have accumulated settled meaning under the common law, a court must infer, unless the statute otherwise dictates, that Congress means to incorporate the established meaning of those terms. Under the common law vicarious liability standard, “the ability to block infringers access to a particular environment for any reason whatsoever is evidence of the right and ability to supervise.” Arista Records LLC v. Usenet.com, Inc., 633 F.Supp.2d 124, 157 (S.D.N.Y. 2009). To adopt that principle in the DMCA context, however, would render the statute internally inconsistent. Section 512(c) actually presumes that service providers have the ability to “block ... access” to infringing material. Indeed, a service provider who has knowledge or awareness of infringing material or who receives a takedown notice from a copyright holder is required to “remove, or disable access to, the material” in order to claim the benefit of the safe harbor. 17 U.S.C. § 512(c)(1)(A)(iii) & (C). But in taking such action, the service provider would — in the plaintiffs’ analysis — be admitting the “right and ability to control” the infringing material. Thus, the prerequisite to safe harbor protection under § 512(c)(1)(A)(iii) & (C) would at the same time be a disqualifier under § 512(c)(1)(B).

Moreover, if Congress had intended § 512(c)(1)(B) to be coextensive with vicarious liability, the statute could have accomplished that result in a more direct manner.

In any event, the foregoing tension — elsewhere described as a “predicament” and a “catch-22” — is sufficient to establish that the control provision “dictates” a departure from the common law vicarious liability standard. Accordingly, we conclude that the “right and ability to control” infringing activity under § 512(c)(1)(B) requires something more than the ability to remove or block access to materials posted on a service provider’s website. The remaining — and more difficult — question is how to define the “something more” that is required.

To date, only one court has found that a service provider had the right and ability to control infringing activity under § 512(c)(1)(B). In Perfect 10, Inc. v. Cybernet Ventures, Inc., 213 F.Supp.2d 1146 (C.D.Cal.2002), the court found control where the service provider instituted a monitoring program by which user websites received “detailed instructions regard[ing] issues of layout, appearance, and content.” Id. at 1173. The service provider also forbade certain types of content and refused access to users who failed to comply with its instructions. Id. Similarly, inducement of copyright infringement under Metro-Goldwyn-Mayer Studios Inc. v. Grokster, Ltd., 545 U.S. 913, (2005), which “premises liability on purposeful, culpable expression and conduct,” id. at 937, might also rise to the level of control under § 512(c)(1)(B). Both of these examples involve a service provider exerting substantial influence on the activities of users, without necessarily — or even frequently — acquiring knowledge of specific infringing activity.

In light of our holding that § 512(c)(1)(B) does not include a specific knowledge requirement, we think it prudent to remand to the District Court to consider in the first instance whether the plaintiffs have adduced sufficient evidence to allow a reasonable jury to conclude that YouTube had the right and ability to control the infringing activity and received a financial benefit directly attributable to that activity.

C. “By Reason of” Storage: § 512(c)(1)

The § 512(c) safe harbor is only available when the infringement occurs “by reason of the storage at the direction of a user of material that resides on a system or network controlled or operated by or for the service provider.” 17 U.S.C. § 512(c)(1). In this case, the District Court held that YouTube’s software functions fell within the safe harbor for infringements that occur “by reason of” user storage. Viacom, 718 F.Supp.2d at 526 (noting that a contrary holding would “confine[] the word ‘storage’ too narrowly to meet the statute’s purpose”). For the reasons that follow, we affirm that holding with respect to three of the challenged software functions — the conversion (or “transcoding”) of videos into a standard display format, the playback of videos on “watch” pages, and the “related videos” function. We remand for further fact-finding with respect to a fourth software function, involving the third-party syndication of videos uploaded to YouTube.

[The statute’s structure and language make clear that service providers seeking protection under §512(c) are not confined to passive storage functions; unlike the narrower “conduit only” category in §512(a), §512(c) applies broadly to providers of online services like YouTube and encompasses more than mere electronic storage lockers.]

The relevant case law makes clear that the § 512(c) safe harbor extends to software functions performed for the purpose of facilitating access to user-stored material. Two of the software functions challenged here — transcoding and playback — were expressly considered by our sister Circuit in Shelter Capital, which held that liability arising from these functions occurred “by reason of the storage at the direction of a user.” 17 U.S.C. § 512(c); see Shelter Capital, 667 F.3d at 1027-28, 1031. Transcoding involves “making copies of a video in a different encoding scheme” in order to render the video “viewable over the Internet to most users.” The playback process involves “delivering copies of YouTube videos to a user’s browser cache” in response to a user request. The District Court correctly found that to exclude these automated functions from the safe harbor would eviscerate the protection afforded to service providers by § 512(c).

A similar analysis applies to the “related videos” function, by which a YouTube computer algorithm identifies and displays “thumbnails” of clips that are “related” to the video selected by the user. The plaintiffs claim that this practice constitutes content promotion, not “access” to stored content, and therefore falls beyond the scope of the safe harbor. Citing similar language in the Racketeer Influenced and Corrupt Organizations Act, and the Clayton Act, the plaintiffs argue that the statutory phrase “by reason of” requires a finding of proximate causation between the act of storage and the infringing activity. But even if the plaintiffs are correct that § 512(c) incorporates a principle of proximate causation — a question we need not resolve here — the indexing and display of related videos retain a sufficient causal link to the prior storage of those videos. The record makes clear that the related videos algorithm “is fully automated and operates solely in response to user input without the active involvement of YouTube employees.” Furthermore, the related videos function serves to help YouTube users locate and gain access to material stored at the direction of other users. Because the algorithm is closely related to, and follows from, the storage itself, and is narrowly directed toward providing access to material stored at the direction of users, we conclude that the related videos function is also protected by the § 512(c) safe harbor.

The final software function at issue here — third-party syndication — is the closest case. In or around March 2007, YouTube transcoded a select number of videos into a format compatible with mobile devices and “syndicated” or licensed the videos to Verizon Wireless and other companies. The plaintiffs argue — with some force — that business transactions do not occur at the “direction of a user” within the meaning of § 512(c)(1) when they involve the manual selection of copyrighted material for licensing to a third party. The parties do not dispute, however, that none of the clips-in-suit were among the approximately 2,000 videos provided to Verizon Wireless. In order to avoid rendering an advisory opinion on the outer boundaries of the storage provision, we remand for fact-finding on the question of whether any of the clips-in-suit were in fact syndicated to any other third party.

Questions

(1) How did the court treat internal YouTube communications (e.g., emails discussing infringing clips) in assessing potential “actual” or “red flag” knowledge? For that matter, how does the court distinguish between “actual knowledge” and “red flag” knowledge? Is the court’s interpretation convincing?

(2) According to the Second Circuit, how does the doctrine of willful blindness interact with the DMCA’s safe harbor provisions?

(3) How did the court interpret the “right and ability to control” requirement under §512(c)(1)(B)? In what way did it differ from the District Court’s approach? What is the “something more” the Viacom court was referring to when considering whether the service provider had “the right and ability to control infringing activity” under § 512(c)(1)(B)?

(4) Is it weird that the Ninth Circuit and the Second Circuit use inducement, a branch of contributory liability, to give content to the part of Section 512(c) that appears to have been modeled on vicarious liability (512(c)(1)(B))?

(5) Which YouTube software functions did the court find to be protected under §512(c), and why?

Notes and questions

(1) In another video sharing case, Capitol Records, LLC v. Vimeo, LLC, 826 F.3d 78 (2d Cir. 2016), the Second Circuit held that the fact that Vimeo employees viewed a video containing a recognizable copyrighted song was not sufficient to establish red flag knowledge. The court elaborated:

The hypothetical “reasonable person” to whom infringement must be obvious is an ordinary person—not endowed with specialized knowledge or expertise concerning music or the laws of copyright. Furthermore, as noted above, § 512(m) makes clear that the service provider’s personnel are under no duty to “affirmatively seek” indications of infringement. The mere fact that an employee of the service provider has viewed a video posted by a user (absent specific information regarding how much of the video the employee saw or the reason for which it was viewed), and that the video contains all or nearly all of a copyrighted song that is “recognizable,” would be insufficient for many reasons to make infringement obvious to an ordinary reasonable person, who is not an expert in music or the law of copyright.

(2) On remand the district court found that the plaintiff could not establish willful blindness in the relevant DMCA sense because all of its arguments boiled down to an affirmative duty to monitor and were thus precluded by Section 512(m).

(3) On remand, the district court held that YouTube’s knowledge of the prevalence of infringing activity, and welcoming the same, did not establish the kind of influence or participation in infringement that would meet the Second Circuit’s “something more” test. Do you agree?

(4) In UMG Recordings, Inc. v. Shelter Capital Partners LLC, 718 F.3d 1006 (9th Cir. 2013) a group of music publishers sued the video sharing website Veoh for copyright infringement. On the subject of the “right and ability to control” provisions of Section 512(c), the Ninth Circuit agreed with the Second Circuit:

… in order to have the “right and ability to control,” the service provider must exert substantial influence on the activities of users. “Substantial influence” may include, as the Second Circuit suggested, high levels of control over activities of users, as in Cybernet. Or it may include purposeful conduct, as in Grokster.

Applying this standard the court held that “Veoh’s interactions with and conduct toward its users did not rise to such a level.” The court recognized that Veoh could have implemented, and did in fact implement, filtering systems and it could have searched for potentially infringing content. But these facts alone did not amount to “substantial influence”. In contrast, the Ninth Circuit found those elements in Columbia Pictures Indus. v. Fung, 710 F.3d 1020, 1043 (9th Cir. 2013), where the record was “replete with instances of Fung actively encouraging infringement, by urging his users to both upload and download particular copyrighted works, providing assistance to those seeking to watch copyrighted films, and helping his users burn copyrighted material onto DVD.”

(5) Over the years since the DMCA was enacted, the common law doctrines of contributory liability and vicarious copyright liability and the analogous provisions of the 512(c) safe harbor have arguably converged. Christopher Cotropia and James Gibson argue that although:

At first glance, this convergence seems unproblematic. After all, uniformity was the DMCA’s goal, and convergence gets us closer to it. But a deeper look reveals that convergence has significantly changed the cost/benefit calculus for those whom the Act governs. The benefits of complying with the Act’s regulatory requirements have decreased, because convergence means that one can ignore the statute and rely solely on the case law. And the costs of complying have increased, because convergence has paradoxically caused courts to conflate the two different sets of standards, mixing and matching them in unpredictable and counterproductive ways to create new, unintended forms of copyright liability and immunity. In short, convergence has led to conflation, which means that the best course for today’s online community is to steer clear of the DMCA altogether.

For more, see Christopher Cotropia and James Gibson Convergence and Conflation in Online Copyright, 105 Iowa Law Review 1027 (2020). Does Cox reverse that convergence? Cotropia and Gibson’s argument was that the case law and the statute had grown so alike that a service provider could safely ignore the DMCA and rely on the common law. After Cox, the common law of contributory infringement is narrower than it was, while the safe harbor’s conditions are unchanged. If the two bodies of law are now diverging rather than converging, which of them is doing the real work of regulating online intermediaries?

(6) The Eleventh Circuit reached the same destination by a different route in Athos Overseas Ltd. Corp. v. YouTube, Inc. (11th Cir. 7 Jan. 2026). Athos, which owns a library of Mexican films, argued that YouTube lost the safe harbor because its copyright management tools could generate lists of potentially infringing uploads, which it said amounted to willful blindness. The court disagreed: tools capable of producing lists of potential infringement do not supply the knowledge the statute requires, and it saw no reason to read § 512 as stripping protection from a provider merely because it had learned facts raising a suspicion of infringement. That would convert the safe harbor into a duty to investigate, which is close to the general monitoring obligation § 512(m) disclaims. The court also held, agreeing with the Second Circuit in Vimeo, that YouTube’s moderation and content management features do not amount to a “right and ability to control” infringing activity, and so did not reach the direct financial benefit question. Read Athos against Mavrix: in both, the platform did more than store, and in both the question was whether doing more costs it the safe harbor. Why do they come out differently?

The status of pre-1972 sound recordings under the DMCA

Although sound recordings have existed since the 19th century, they were only brought within the scope of federal copyright protection on February 15, 1972. This change in the law was prospective only. The Music Modernization Act of 2018 (MMA) eventually established a new regime of protection for pre-1972 sound recordings (see below), but from 1972 to 2018, any protection against copying of pre-1972 sound recordings depended solely on state copyright laws (to the extent such laws are not pre-empted). In Capitol Records, LLC v. Vimeo, LLC, 826 F.3d 78 (2d Cir. 2016), discussed above, the Second Circuit held that the Section 512 safe harbors are effective against claims of infringement based on state copyright laws with respect to pre-1972 sound recordings.

The MMA established a new regime of protection for pre-1972 sound recordings and also applied the Section 512 safe harbors to those activities.

17 U.S. Code § 1401. Unauthorized use of pre-1972 sound recordings

(a) In General.—(1)Unauthorized acts.—Anyone who [] without the consent of the rights owner, engages in covered activity with respect to a sound recording fixed before February 15, 1972, shall be subject to the remedies provided in sections 502 through 505 and 1203 to the same extent as an infringer of copyright or a person that engages in unauthorized activity under chapter 13.

(l) Definitions.—In this section: (1)Covered activity.—The term “covered activity” means any activity that the copyright owner of a sound recording would have the exclusive right to do or authorize under section 106 or 602, or that would violate section 1201 or 1202, if the sound recording were fixed on or after February 15, 1972.

(f)(3) Material online.—Section 512 shall apply to a claim under subsection (a) with respect to a sound recording fixed before February 15, 1972.

Designating an agent to receive notifications of claimed infringement

Obtaining safe harbor protection under Section 512(c) also requires service providers to comply with the seemingly perfunctory step of designating an agent to receive notifications of claimed infringement and providing certain information to the Copyright Office, see Section 512(c)(2).

17 US Code § 512 (c) Information Residing on Systems or Networks At Direction of Users.—

(2) Designated agent.— The limitations on liability established in this subsection apply to a service provider only if the service provider has designated an agent to receive notifications of claimed infringement described in paragraph (3), by making available through its service, including on its website in a location accessible to the public, and by providing to the Copyright Office, substantially the following information:

(A) the name, address, phone number, and electronic mail address of the agent.

(B) other contact information which the Register of Copyrights may deem appropriate.

The Register of Copyrights shall maintain a current directory of agents available to the public for inspection, including through the Internet, and may require payment of a fee by service providers to cover the costs of maintaining the directory.

Note that a parent company’s designation of an agent to address infringement claims did not extend to its subsidiary and also “A service provider cannot retroactively qualify for the safe harbor for infringements occurring before the proper designation of an agent under the statute.” See, BWP Media USA Inc. v. Hollywood Fan Sites LLC, 2015 WL 3971750, at *3 (S.D.N.Y. June 30, 2015).

What activities are at the direction of the user for the purposes of Section 512(c)?

Mavrix Photographs, LLC v. LiveJournal, Inc., 873 F.3d 1045 (9th Cir. 2017)

Circuit Judge Richard A. Paez

[Mavrix Photographs, LLC, a celebrity photography company brought an infringement action against the owner of a social media platform that allowed users to post content in user-created thematic communities. The case involved a LiveJournal blog called Oh No They Didn’t! (“ONTD”) that republishes reader submissions about celebrity gossip. The key issue in Mavrix was whether, in light of the role that moderators played, LiveJournal could establish that the infringing material the plaintiff complained of met the 512(c) threshold of being stored “at the direction of the user.” ]

When ONTD was created, like other LiveJournal communities, it was operated exclusively by volunteer moderators. LiveJournal was not involved in the day-to-day operation of the site. ONTD, however, grew in popularity to 52 million page views per month in 2010 and attracted LiveJournal’s attention. By a significant margin, ONTD is LiveJournal’s most popular community and is the only community with a “household name.” In 2010, LiveJournal sought to exercise more control over ONTD so that it could generate advertising revenue from the popular community. LiveJournal hired a then active moderator, Brendan Delzer, to serve as the community’s full time “primary leader.” By hiring Delzer, LiveJournal intended to “take over” ONTD, grow the site, and run ads on it.

As the “primary leader,” Delzer instructs ONTD moderators on the content they should approve and selects and removes moderators on the basis of their performance. Delzer also continues to perform moderator work, reviewing and approving posts alongside the other moderators whom he oversees. While Delzer is paid and expected to work full time, the other moderators are “free to leave and go and volunteer their time in any way they see fit.” In his deposition, Mark Ferrell, the General Manager of LiveJournal’s U.S. office, explained that Delzer “acts in some capacities as a sort of head maintainer” and serves in an “elevated status” to the other moderators. Delzer, on the other hand, testified at his deposition that he does not serve as head moderator and that ONTD has no “primary leader.” …

LiveJournal must make a threshold showing that Mavrix’s photographs were stored at the direction of the user. “Storage,” in this context, has a unique meaning. Congress explained that “examples of such storage include providing server space for a user’s web site, for a chatroom, or other forum in which material may be posted at the direction of users.” S. Rep. 105-190, at 43 (1998). We have held that storage “encompasses the access-facilitating processes” in addition to storage itself. UMG Recordings, Inc. v. Shelter Capital Partners LLC, 718 F.3d 1006, 1016 (9th Cir.2013) (rejecting a claim that the safe harbor addresses mere storage lockers). We reasoned that rather than requiring “that the infringing conduct be storage,” the statutory language allows for infringement “by reason of the storage at the direction of a user.” The district court held that although moderators screened and publicly posted all of the ONTD posts, the posts were at the direction of the user. The district court focused on the users’ submission of infringing photographs to LiveJournal rather than LiveJournal’s screening and public posting of the photographs. A different safe harbor, § 512(a), protects service providers from liability for the passive role they play when users submit infringing material to them. 17 U.S.C. § 512(a). The § 512(c) safe harbor focuses on the service provider’s role in making material stored by a user publicly accessible on its site. See Shelter Capital, 718 F.3d at 1018; S. Rep. No. 105-190, at 43-44 (1998). Contrary to the district court’s view, public accessibility is the critical inquiry. In the context of this case, that inquiry turns on the role of the moderators in screening and posting users’ submissions and whether their acts may be attributed to LiveJournal.

Mavrix, relying on the common law of agency, argues that the moderators are LiveJournal’s agents, making LiveJournal liable for the moderators’ acts. The district court erred in rejecting this argument.

Statutes are presumed not to disturb the common law, unless the language of a statute is clear and explicit for this purpose. Pursuant to this principle, the Supreme Court and this court have applied common law in cases involving federal copyright law, including the DMCA. … We therefore have little difficulty holding that common law agency principles apply to the analysis of whether a service provider like LiveJournal is liable for the acts of the ONTD moderators.

In light of the summary judgment record, we conclude that there are genuine issues of material fact as to whether the moderators are LiveJournal’s agents. The factual dispute is evident when we apply common law agency principles to the evidentiary record.

“Agency is the fiduciary relationship that arises when one person (a ‘principal’) manifests assent to another person (an ‘agent’) that the agent shall act on the principal’s behalf and subject to the principal’s control, and the agent manifests assent or otherwise consents so to act.” Restatement (Third) Of Agency § 1.01 (Am. Law Inst. 2006). For an agency relationship to exist, an agent must have authority to act on behalf of the principal and “the person represented [must have] a right to control the actions of the agent.” Restatement (Third) Of Agency § 1.01, cmt. c (Am. Law Inst. 2006).

An agency relationship may be created through actual or apparent authority. Actual authority arises through “the principal’s assent that the agent take action on the principal’s behalf.” Restatement (Third) of Agency § 3.01 (Am. Law Inst. 2006). LiveJournal argues that it did not assent to the moderators acting on its behalf. Mavrix, however, presented evidence that LiveJournal gave its moderators explicit and varying levels of authority to screen posts. Although LiveJournal calls the moderators “volunteers,” the moderators performed a vital function in LiveJournal’s business model. There is evidence in the record that LiveJournal gave moderators express directions about their screening functions, including criteria for accepting or rejecting posts. Unlike other sites where users may independently post content, LiveJournal relies on moderators as an integral part of its screening and posting business model. LiveJournal also provides three different levels of authority: moderators review posts to ensure they contain celebrity gossip and not pornography or harassment, maintainers delete posts and can remove moderators, and owners can remove maintainers. Genuine issues of material fact therefore exist regarding whether the moderators had actual authority.

Apparent authority arises by “a person’s manifestation that another has authority to act with legal consequences for the person who makes the manifestation, when a third party reasonably believes the actor to be authorized and the belief is traceable to the manifestation.” Restatement (Third) of Agency § 3.03 (Am. Law Inst. 2006); see also Hawaiian Paradise Park Corp. v. Friendly Broad. Co., 414 F.2d 750, 756 (9th Cir. 1969). “The principal’s manifestations giving rise to apparent authority may consist of direct statements to the third person, directions to the agent to tell something to the third person, or the granting of permission to the agent to perform acts under circumstances which create in him a reputation of authority.” Hawaiian Paradise Park, 414 F.2d at 756.

LiveJournal selected moderators and provided them with specific directions. Mavrix presented evidence that LiveJournal users may have reasonably believed that the moderators had authority to act for LiveJournal. One user whose post was removed pursuant to a DMCA notice complained to LiveJournal “I’m sure my entry does not violate any sort of copyright law. ... I followed [ONTD’s] formatting standards and the moderators checked and approved my post.” The user relied on the moderators’ approval as a manifestation that the post complied with copyright law, and the user appeared to believe the moderators acted on behalf of LiveJournal. Such reliance is likely traceable to LiveJournal’s policy of providing explicit roles and authority to the moderators. Accordingly, genuine issues of material fact exist regarding whether there was an apparent authority relationship.

Whether an agency relationship exists also depends on the level of control a principal exerts over the agent. Evidence presented by Mavrix shows that LiveJournal maintains significant control over ONTD and its moderators. Delzer gives the moderators substantive supervision and selects and removes moderators on the basis of their performance, thus demonstrating control. Delzer also exercises control over the moderators’ work schedule. For example, he added a moderator from Europe so that there would be a moderator who could work while other moderators slept. Further demonstrating LiveJournal’s control over the moderators, the moderators’ screening criteria derive from rules ratified by LiveJournal.

On the other hand, ONTD moderators “are free to leave and go and volunteer their time in any way they see fit.” In addition, the moderators can reject submissions for reasons other than those provided by the rules, which calls into question the level of control that LiveJournal exerts over their conduct. This evidence raises genuine issues of material fact regarding the level of control LiveJournal exercised over the moderators. From the evidence currently in the record, reasonable jurors could conclude that an agency relationship existed.

We turn briefly to a related issue that the fact finder must resolve in the event there is a finding that the moderators are agents of LiveJournal. In that event, the fact finder must assess whether Mavrix’s photographs were indeed stored at the direction of the users in light of the moderators’ role in screening and posting the photographs. Infringing material is stored at the direction of the user if the service provider played no role in making that infringing material accessible on its site or if the service provider carried out activities that were “narrowly directed” towards enhancing the accessibility of the posts. See UMG Recordings, Inc. v. Veoh Networks, Inc., 620 F.Supp.2d 1081, 1092 (C.D. Cal. 2008); see also Shelter Capital, 718 F.3d at 1018. Accessibility-enhancing activities include automatic processes, for example, to reformat posts or perform some technological change. Shelter Capital, 718 F.3d at 1020 (referring to accessibility-enhancing activities as those where the service provider did “not actively participate in or supervise file uploading”). Some manual service provider activities that screen for infringement or other harmful material like pornography can also be accessibility-enhancing. Indeed, § 512(m) of the DMCA provides that no liability will arise from “a service provider monitoring its service or affirmatively seeking facts indicating infringing activity.” Id. at 1022 (quoting 17 U.S.C. § 512(m)). [In a footnote the court explains that the district court did not assess whether the moderators’ review of posts exceeded accessibility-enhancing activities because it focused on submission rather than public accessibility and did not determine whether the moderators were agents.]

The ONTD moderators manually review submissions and publicly post only about one-third of submissions. The moderators review the substance of posts; only those posts relevant to new and exciting celebrity gossip are approved. The question for the fact finder is whether the moderators’ acts were merely accessibility-enhancing activities or whether instead their extensive, manual, and substantive activities went beyond the automatic and limited manual activities we have approved as accessibility-enhancing.

Because the district court focused on the users’ submission of Mavrix’s photographs rather than on ONTD’s role in making those photographs publicly accessible and rejected Mavrix’s argument that unpaid moderators could be agents of LiveJournal, the district court erred in granting summary judgment to LiveJournal. Genuine issues of material fact exist as to whether the moderators were LiveJournal’s agents. Accordingly, remand is warranted. In assessing LiveJournal’s threshold eligibility for the § 512(c) safe harbor, the fact finder must resolve the factual dispute regarding the moderators’ status as LiveJournal’s agents and in light of that determination, whether LiveJournal showed that Mavrix’s photographs were stored at the direction of the users.

Notes and questions

(1) According to Circuit Judge Paez, what specific issue regarding “ONTD” (Oh No They Didn’t) prevented LiveJournal from claiming safe harbor protection under Section 512(c)?

(2) What distinction does the court make between LiveJournal’s storage of user photographs that were posted directly versus those that were screened by moderators, and why is this distinction legally significant?

(3) How does the court’s reference to the “red flag” knowledge standard relate to LiveJournal’s potential liability, and what example does the text provide of content that might constitute such knowledge?

(4) UMG Recordings, Inc. v. Shelter Capital Partners LLC, 718 F.3d 1006 (9th Cir. 2013) held that accessibility-enhancing activities include automatic processes, for example, to reformat posts or perform some technological change. The same court would have also regarded some manual service provider activities that screen for infringement or other harmful material like pornography as accessibility-enhancing. Furthermore, Section 512(m) of the DMCA provides that no liability will arise from “a service provider monitoring its service or affirmatively seeking facts indicating infringing activity.” Is Mavrix Photographs consistent with Shelter Capital? What are the risks inherent in different kinds of content moderation after the Ninth Circuit’s opinion in Mavrix Photographs?

(5) The Second Circuit took up the same question in McGucken v. Shutterstock, Inc., 2026 WL 364412 (2d Cir. 10 Feb. 2026), and the facts are a long way from a message board. Shutterstock is a curated stock-image marketplace: contributors upload, but Shutterstock reviews, tags, categorizes and prices what it accepts, and it built what the court called an image pipeline through which everything passes. McGucken’s argument was that images therefore do not appear on the platform “at the direction of a user” at all — the platform decides what appears. The Second Circuit held that summary judgment for Shutterstock could not stand on this record. Two issues had to go to trial: whether the infringing activity occurred “by reason of the storage at the direction of a user,” and whether Shutterstock had the right and ability to control it. Shutterstock had otherwise satisfied the safe harbor’s requirements, so everything turned on those two questions.

(6) Mavrix and McGucken are asking one question in two settings: how much curation can a platform perform before what it hosts stops being stored “at the direction of a user” and starts being its own editorial product? Moderators approving submissions to a fan community, and a stock agency reviewing and pricing images for sale, sit at very different points on that scale — and note that Athos, above, treats YouTube’s moderation as not even raising the issue. Where would you put an algorithmic recommendation feed that decides which stored material anyone actually sees?

Liability for misrepresentation under 512(f)

For a rightsholder notification to be effective under the DMCA, it must identify the infringed work and provide enough information for the service provider to locate the material that should be blocked or removed. Under Section 512(c)(3)(A)(v-vi), a notification must also attest to the complaining party’s “good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law,” and it must further promise that “the information in the notification is accurate, and under penalty of perjury, that the complaining party is authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.”

Section 512(f) establishes a remedy for any user who is injured by a knowingly false representation in a takedown notice. The caselaw determining the scope of this potential liability begins with Online Policy Group v. Diebold, Inc., 337 F. Supp. 2d 1195 (N.D. Cal. 2004). In the Diebold case, the district court applied an objective standard to section 512(f) and held that the term “knowingly” encompassed actual knowledge of falsity and also instances where a party “should have known if it acted with reasonable care or diligence, or would have had no substantial doubt had it been acting in good faith.”

However, very shortly thereafter, the Ninth Circuit in Rossi v. Motion Picture Ass’n of America, 391 F.3d 1000 (9th Cir. 2004) held that the good faith belief requirement “encompasses a subjective, rather than objective, standard.” Under a subjective standard, negligent, unreasonable, or overzealous assertions of infringement do not violate the good-faith requirement and do not constitute an actionable misrepresentation under section 512(f). This narrow reading of the DMCA’s statutory misrepresentation remedy is doubly significant because Diebold held that the DMCA remedy preempts state law causes of action, such as tortious interference with contract, which might have otherwise provided a remedy. However, the Ninth Circuit’s decision in Lenz v. Universal Music Corp., 815 F.3d 1145 (9th Cir. 2015) suggests that the subjective standard for actionable misrepresentation under section 512(f) is less forgiving to sophisticated copyright owners than it may have first appeared.

The case of the dancing baby

Summary adapted from Matthew Sag, Internet Safe Harbors and the Transformation of Copyright Law, 93 Notre Dame Law Review 499 (2017).

Dancing Baby Video (Screenshot)

On February 7, 2007, Stephanie Lenz uploaded a twenty-nine second home video capturing her children dancing in the family’s kitchen to the song Let’s Go Crazy by Prince. The “dancing baby video” is utterly unremarkable except for the eight years (and counting) of litigation that it provoked. At the time, Universal Music Corporation administered the relevant copyrights on behalf of Prince. Universal issued a DMCA takedown notice to YouTube on June 4, 2007.

YouTube removed the video the following day. Lenz issued a counternotification, and her video was eventually restored some six weeks later. The dancing baby video was targeted for removal by Universal as part of a broader effort to purge unauthorized Prince titles from YouTube—Prince apparently had strong feelings on the subject, and Universal was keen to make him happy. This is how the legal assistant at Universal who reviewed the video described his process:

I put a video on the list that embodied a Prince composition in some way if the—there was a significant use of it, of the composition, specifically if the song was recognizable, was in a significant portion of the video or was the focus of the video.

The assistant determined that the dancing baby video violated Prince’s copyright because of its title, Let’s Go Crazy # 1; because he recognized the song in the background “right off the bat,” and because “the song was loud and played through the entire video.” The assistant also based his decision on the fact that the audio track “included a voice asking the children whether they liked the music.” When Universal issued its takedown notice, it attested that it had “a good faith belief that the above-described activity is not authorized by the copyright owner, its agent, or the law.” However, at no stage did the legal assistant, nor anyone else in Universal’s legal department, consider whether the dancing baby video qualified as fair use.

Universal’s omission was unfortunate because it is beyond serious question that the dancing baby video qualifies as fair use. The video opens with the camera focused on a baby in a red jumper pushing a red cart along a kitchen floor in a cacophony of noise. The baby turns to the camera and, off screen, a woman asks “what do you think of the music?” Another child briefly enters the frame and the sounds of Prince singing “c’mon baby let’s get nuts” become audible and recognizable, at least to the average Prince fan. For the remaining seventeen seconds of the video, the baby stays in the center of the frame, not exactly dancing but apparently enjoying the music. In the background, there is adult laughter as another child does laps of the kitchen. Apart from the music, the general domestic background noise is loud throughout the video. The dancing baby video captures a child’s reaction to a well-known pop song in an ordinary family setting.

The child and its reaction, not the music, are the focus of the video. Any objective observer could see this. Rightsholders place great value on so-called synchronization rights: the right to synchronize music with otherwise unrelated visual media. However, the dancing baby video could not be mistaken for an ordinary synchronization. Although the music is identifiable, only a relatively brief part of the song is featured, and the audio quality is poor. No one would watch or listen to this video in order to appreciate the Prince classic. Any objective observer familiar with the fair use doctrine should have recognized that the dancing baby video was fair use.

As a result, the dancing baby video set the stage for an important test case on the relationship between the DMCA notice-and-takedown procedures and fair use. The district court in Lenz v. Universal Music Corp., 572 F. Supp. 2d 1150 (N.D. Cal. 2008) held, in denying a motion to dismiss, that an allegation that a copyright owner acted in bad faith by issuing a takedown notice without proper consideration of the fair use doctrine was sufficient to state a misrepresentation claim pursuant to section 512(f) of the DMCA.

Lenz v. Universal Music Corp., 815 F.3d 1145 (9th Cir. 2015)

Circuit Judge Tallman

Section 512(c) permits service providers, e.g., YouTube or Google, to avoid copyright infringement liability for storing users’ content if — among other requirements — the service provider “expeditiously” removes or disables access to the content after receiving notification from a copyright holder that the content is infringing. Section 512(c)(3)(A) sets forth the elements that such a “takedown notification” must contain. These elements include identification of the copyrighted work, identification of the allegedly infringing material, and, critically, a statement that the copyright holder believes in good faith the infringing material “is not authorized by the copyright owner, its agent, or the law.” Id. § 512(c)(3)(A). The procedures outlined in § 512(c) are referred to as the DMCA’s “takedown procedures.”

To avoid liability for disabling or removing content, the service provider must notify the user of the takedown. Id. § 512(g)(1)-(2). The user then has the option of restoring the content by sending a counter-notification, which must include a statement of “good faith belief that the material was removed or disabled as a result of mistake or misidentification....” Id. § 512(g)(3)(C). Upon receipt of a valid counter-notification, the service provider must inform the copyright holder of the counter-notification and restore the content within “not less than 10, nor more than 14, business days,” unless the service provider receives notice that the copyright holder has filed a lawsuit against the user seeking to restrain the user’s infringing behavior. Id. § 512(g)(2)(B)-(C). The procedures outlined in § 512(g) are referred to as the DMCA’s “put-back procedures.”

If an entity abuses the DMCA, it may be subject to liability under § 512(f). That section provides: “Any person who knowingly materially misrepresents under this section — (1) that material or activity is infringing, or (2) that material or activity was removed or disabled by mistake or misidentification, shall be liable for any damages....” Id. § 512(f). Subsection (1) generally applies to copyright holders and subsection (2) generally applies to users. Only subsection (1) is at issue here.

B

We must first determine whether 17 U.S.C. § 512(c)(3)(A)(v) requires copyright holders to consider whether the potentially infringing material is a fair use of a copyright under 17 U.S.C. § 107 before issuing a takedown notification. Section 512(c)(3)(A)(v) requires a takedown notification to include a “statement that the complaining party has a good faith belief that the use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.” The parties dispute whether fair use is an authorization under the law as contemplated by the statute — which is so far as we know an issue of first impression in any circuit across the nation. “Canons of statutory construction dictate that if the language of a statute is clear, we look no further than that language in determining the statute’s meaning.... A court looks to legislative history only if the statute is unclear.” United States v. Lewis, 67 F.3d 225, 228-29 (9th Cir.1995) (citations omitted). We agree with the district court and hold that the statute unambiguously contemplates fair use as a use authorized by the law.

Fair use is not just excused by the law, it is wholly authorized by the law. In 1976, Congress codified the application of a four-step test for determining the fair use of copyrighted works:

Notwithstanding the provisions of sections 106 and 106A, the fair use of a copyrighted work, ... for purposes such as criticism, comment, news reporting, teaching (including multiple copies for classroom use), scholarship, or research, is not an infringement of copyright. In determining whether the use made of a work in any particular case is a fair use the factors to be considered shall include —

(1) the purpose and character of the use, including whether such use is of a commercial nature or is for nonprofit educational purposes;

(2) the nature of the copyrighted work;

(3) the amount and substantiality of the portion used in relation to the copyrighted work as a whole; and

(4) the effect of the use upon the potential market for or value of the copyrighted work.

The fact that a work is unpublished shall not itself bar a finding of fair use if such finding is made upon consideration of all the above factors.

17 U.S.C. § 107 (emphasis added). The statute explains that the fair use of a copyrighted work is permissible because it is a non-infringing use.

While Title 17 of the United States Code (“Copyrights”) does not define the term “authorize” or “authorized,” “[w]hen there is no indication that Congress intended a specific legal meaning for the term, the court may look to sources such as dictionaries for a definition.” United States v. Mohrbacher, 182 F.3d 1041, 1048 (9th Cir.1999). Black’s Law Dictionary defines “authorize” as “1. To give legal authority; to empower” and “2. To formally approve; to sanction.” Authorize, Black’s Law Dictionary (10th ed. 2014). Because 17 U.S.C. § 107 both “empowers” and “formally approves” the use of copyrighted material if the use constitutes fair use, fair use is “authorized by the law” within the meaning of § 512(c). See also 17 U.S.C. § 108(f)(4) (“Nothing in this section in any way affects the right of fair use as provided by section 107....” (emphasis added)).

Universal’s sole textual argument is that fair use is not “authorized by the law” because it is an affirmative defense that excuses otherwise infringing conduct. Universal’s interpretation is incorrect as it conflates two different concepts: an affirmative defense that is labeled as such due to the procedural posture of the case, and an affirmative defense that excuses impermissible conduct. Supreme Court precedent squarely supports the conclusion that fair use does not fall into the latter camp: “anyone who ... makes a fair use of the work is not an infringer of the copyright with respect to such use.” Sony Corp. of Am. v. Universal City Studios, Inc., 464 U.S. 417, 433 (1984).

Given that 17 U.S.C. § 107 expressly authorizes fair use, labeling it as an affirmative defense that excuses conduct is a misnomer:

Although the traditional approach is to view “fair use” as an affirmative defense, this writer, speaking only for himself, is of the opinion that it is better viewed as a right granted by the Copyright Act of 1976. Originally, as a judicial doctrine without any statutory basis, fair use was an infringement that was excused — this is presumably why it was treated as a defense. As a statutory doctrine, however, fair use is not an infringement. Thus, since the passage of the 1976 Act, fair use should no longer be considered an infringement to be excused; instead, it is logical to view fair use as a right. Regardless of how fair use is viewed, it 1153*1153 is clear that the burden of proving fair use is always on the putative infringer.

Bateman v. Mnemonics, Inc., 79 F.3d 1532, 1542 n. 22 (11th Cir.1996) (Birch, J.). We agree. Cf. Lydia Pallas Loren, Fair Use: An Affirmative Defense?, 90 Wash. L. Rev. 685, 688 (2015) (“Congress did not intend fair use to be an affirmative defense — a defense, yes, but not an affirmative defense.”). Fair use is therefore distinct from affirmative defenses where a use infringes a copyright, but there is no liability due to a valid excuse, e.g., misuse of a copyright, Practice Management Information Corp. v. American Medical Ass’n, 121 F.3d 516, 520 (9th Cir.1997), and laches, Danjaq LLC v. Sony Corp., 263 F.3d 942, 950-51 (9th Cir.2001).

Universal concedes it must give due consideration to other uses authorized by law such as compulsory licenses. The introductory language in 17 U.S.C. § 112 for compulsory licenses closely mirrors that in the fair use statute. Compare 17 U.S.C. § 112(a)(1) (“Notwithstanding the provisions of section 106, ... it is not an infringement of copyright for a transmitting organization entitled to transmit to the public a performance or display of a work... to make no more than one copy or phonorecord of a particular transmission program embodying the performance or display....”), with id. § 107 (“Notwithstanding the provisions of sections 106 and 106A, the fair use of a copyrighted work... is not an infringement of copyright.”). That fair use may be labeled as an affirmative defense due to the procedural posture of the case is no different than labeling a license an affirmative defense for the same reason. Compare Campbell v. Acuff-Rose Music, Inc., 510 U.S. 569, 573 & n. 3, 590 (1994) (stating that “fair use is an affirmative defense” where the district court converted a motion to dismiss based on fair use into a motion for summary judgment), with A & M Records, Inc. v. Napster, Inc., 239 F.3d 1004, 1025-26 (9th Cir.2001) (“Napster contends that ... the district court improperly rejected valid affirmative defenses of ... implied license....”). Thus, Universal’s argument that it need not consider fair use in addition to compulsory licenses rings hollow.

Even if, as Universal urges, fair use is classified as an “affirmative defense,” we hold — for the purposes of the DMCA — fair use is uniquely situated in copyright law so as to be treated differently than traditional affirmative defenses. We conclude that because 17 U.S.C. § 107 created a type of non-infringing use, fair use is “authorized by the law” and a copyright holder must consider the existence of fair use before sending a takedown notification under § 512(c).

C

We must next determine if a genuine issue of material fact exists as to whether Universal knowingly misrepresented that it had formed a good faith belief the video did not constitute fair use. This inquiry lies not in whether a court would adjudge the video as a fair use, but whether Universal formed a good faith belief that it was not. Contrary to the district court’s holding, Lenz may proceed under an actual knowledge theory, but not under a willful blindness theory.

1

Though Lenz argues Universal should have known the video qualifies for fair use as a matter of law, we have already decided a copyright holder need only form a subjective good faith belief that a use is not authorized. Rossi v. Motion Picture Ass’n of Am. Inc., 391 F.3d 1000 (9th Cir.2004). In Rossi, we explicitly held that “the ‘good faith belief’ requirement in § 512(c)(3)(A)(v) encompasses a subjective, rather than objective standard,” and we observed that “Congress understands this distinction.” Id. at 1004. We further held:

When enacting the DMCA, Congress could have easily incorporated an objective standard of reasonableness. The fact that it did not do so indicates an intent to adhere to the subjective standard traditionally associated with a good faith requirement....

In § 512(f), Congress included an expressly limited cause of action for improper infringement notifications, imposing liability only if the copyright owner’s notification is a knowing misrepresentation. A copyright owner cannot be liable simply because an unknowing mistake is made, even if the copyright owner acted unreasonably in making the mistake. Rather, there must be a demonstration of some actual knowledge of misrepresentation on the part of the copyright owner.

Id. at 1004-05 (citations omitted). Neither of these holdings are dictum. See United States v. Johnson, 256 F.3d 895, 914 (9th Cir.2001) (en banc) (“[W]here a panel confronts an issue germane to the eventual resolution of the case, and resolves it after reasoned consideration in a published opinion, that ruling becomes the law of the circuit, regardless of whether doing so is necessary in some strict logical sense.”). We therefore judge Universal’s actions by the subjective beliefs it formed about the video.

2

Universal faces liability if it knowingly misrepresented in the takedown notification that it had formed a good faith belief the video was not authorized by the law, i.e., did not constitute fair use. Here, Lenz presented evidence that Universal did not form any subjective belief about the video’s fair use — one way or another — because it failed to consider fair use at all, and knew that it failed to do so. Universal nevertheless contends that its procedures, while not formally labeled consideration of fair use, were tantamount to such consideration. Because the DMCA requires consideration of fair use prior to sending a takedown notification, a jury must determine whether Universal’s actions were sufficient to form a subjective good faith belief about the video’s fair use or lack thereof.3

Footnote 3: Although the panel agrees on the legal principles we discuss herein, we part company with our dissenting colleague over the propriety of resolving on summary judgment Universal’s claim to subjective belief that the copyright was infringed. The dissent would find that no triable issue of fact exists because Universal did not specifically and expressly consider the fair-use elements of 17 U.S.C. § 107. But the question is whether the analysis Universal did conduct of the video was sufficient, not to conclusively establish as a matter of law that the video’s use of Let’s Go Crazy was fair, but to form a subjective good faith belief that the video was infringing on Prince’s copyright. And under the circumstances of this case, that question is for the jury, not this court, to decide.

To be clear, if a copyright holder ignores or neglects our unequivocal holding that it must consider fair use before sending a takedown notification, it is liable for damages under § 512(f). If, however, a copyright holder forms a subjective good faith belief the allegedly infringing material does not constitute fair use, we are in no position to dispute the copyright holder’s belief even if we would have reached the opposite conclusion. A copyright holder who pays lip service to the consideration of fair use by claiming it formed a good faith belief when there is evidence to the contrary is still subject to § 512(f) liability. Cf. Disney Enters., Inc. v. Hotfile Corp., No. 11-cv-20427, 2013 WL 6336286, at *48 (S.D.Fla. Sept. 20, 2013) (denying summary judgment of § 512(f) counterclaim due to “sufficient evidence in the record to suggest that [Plaintiff] Warner intentionally targeted files it knew it had no right to remove”); Rosen v. Hosting Servs., Inc., 771 F.Supp.2d 1219, 1223 (C.D.Cal.2010) (denying summary judgment of § 512(f) counterclaim where the takedown notification listed four URL links that did not contain content matching the description of the purportedly infringed material); Online Policy Grp. v. Diebold, Inc., 337 F.Supp.2d 1195, 1204-05 (N.D.Cal.2004) (“[T]here is no genuine issue of fact that Diebold knew — and indeed that it specifically intended — that its letters to OPG and Swarthmore would result in prevention of publication of that content.... The fact that Diebold never actually brought suit against any alleged infringer suggests strongly that Diebold sought to use the DMCA’s safe harbor provisions — which were designed to protect ISPs, not copyright holders — as a sword to suppress publication of embarrassing content rather than as a shield to protect its intellectual property.”).

3

We hold the willful blindness doctrine may be used to determine whether a copyright holder “knowingly materially misrepresent[ed]” that it held a “good faith belief” the offending activity was not a fair use. See 17 U.S.C. § 512(c)(3)(A)(v), (f). “[T]he willful blindness doctrine may be applied, in appropriate circumstances, to demonstrate knowledge or awareness of specific instances of infringement under the DMCA.” Viacom Int’l, Inc. v. YouTube, Inc., 676 F.3d 19, 35 (2d Cir.2012) (interpreting how a party can establish the “actual knowledge” — a subjective belief — required by § 512(c)(1)(A)(i)); see also UMG Recordings, Inc. v. Shelter Capital Partners LLC, 718 F.3d 1006, 1023 (9th Cir.2013) (“Of course, a service provider cannot willfully bury its head in the sand to avoid obtaining such specific knowledge.” (citing Viacom, 676 F.3d at 31)). But, based on the specific facts presented during summary judgment, we reject the district court’s conclusion that Lenz may proceed to trial under a willful blindness theory.

To demonstrate willful blindness a plaintiff must establish two factors: “(1) the defendant must subjectively believe that there is a high probability that a fact exists and (2) the defendant must take deliberate actions to avoid learning of that fact.” Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754 (2011). “Under this formulation, a willfully blind defendant is one who takes deliberate actions to avoid confirming a high probability of wrongdoing and who can almost be said to have actually known the critical facts.” To meet the Global-Tech test, Lenz must demonstrate a genuine issue as to whether — before sending the takedown notification — Universal (1) subjectively believed there was a high probability that the video constituted fair use, and (2) took deliberate actions to avoid learning of this fair use.

On summary judgment Lenz failed to meet a threshold showing of the first factor. To make such a showing, Lenz must provide evidence from which a juror could infer that Universal was aware of a high probability the video constituted fair use. See United States v. Yi, 704 F.3d 800, 805 (9th Cir.2013). But she failed to provide any such evidence. The district court therefore correctly found that “Lenz does not present evidence suggesting Universal subjectively believed either that there was a high probability any given video might make fair use of a Prince composition or her video in particular made fair use of Prince’s song ‘Let’s Go Crazy.’” Yet the district court improperly denied Universal’s motion for summary judgment on the willful blindness theory because Universal “has not shown that it lacked a subjective belief.” By finding blame with Universal’s inability to show that it “lacked a subjective belief,” the district court improperly required Universal to meet its burden of persuasion, even though Lenz had failed to counter the initial burden of production that Universal successfully carried. Lenz may not therefore proceed to trial on a willful blindness theory.

V

Section 512(f) provides for the recovery of “any damages, including costs and attorneys[‘] fees, incurred by the alleged infringer ... who is injured by such misrepresentation, as the result of the service provider relying upon such misrepresentation in removing or disabling access to the material or activity claimed to be infringing....” 17 U.S.C. § 512(f). We hold a plaintiff may seek recovery of nominal damages for an injury incurred as a result of a § 512(f) misrepresentation.

Universal incorrectly asserts that Lenz must demonstrate she incurred “actual monetary loss.” Section 512(k) provides a definition for “monetary relief” as “damages, costs, attorneys[‘] fees, and any other form of monetary payment.” The term “monetary relief” appears in § 512(a), (b)(1), (c)(1), and (d), but is notably absent from § 512(f). As a result, the damages an alleged infringer may recover under § 512(f) from “any person” are broader than monetary relief. Because Congress specified the recovery of “any damages,” we reject Universal’s contention that Congress did not indicate its intent to depart from the common law presumption that a misrepresentation plaintiff must have suffered a monetary loss.

Lenz may seek recovery of nominal damages due to an unquantifiable harm suffered as a result of Universal’s actions. The DMCA is akin to a statutorily created intentional tort whereby an individual may recover nominal damages for a “knowingly material misrepresent[ation] under this section [512].” 17 U.S.C. § 512(f); cf. Memphis Cmty. Sch. Dist. v. Stachura, 477 U.S. 299, 305 (1986) (“We have repeatedly noted that 42 U.S.C. § 1983 creates a species of tort liability in favor of persons who are deprived of rights, privileges, or immunities secured to them by the Constitution. Accordingly, when § 1983 plaintiffs seek damages for violations of constitutional rights, the level of damages is ordinarily determined according to principles derived from the common law of torts.” (quotation and citations omitted)).

“In a number of common law actions associated with intentional torts, the violation of the plaintiff’s right has generally been regarded as a kind of legal damage in itself. The plaintiff who proves an intentional physical tort to the person or to property can always recover nominal damages.” 3 Dan B. Dobbs et al., The Law of Torts § 480 (2d ed. 2011). The tort need not be physical in order to recover nominal damages. Defamation, for example, permits the recovery of nominal damages:

A nominal damage award can be justified in a tort action only if there is some reason for awarding a judgment in favor of a claimant who has not proved or does not claim a compensable loss with sufficient certainty to justify a recovery of compensatory or actual damages. There may be such a reason in an action for defamation, since a nominal damage award serves the purpose of vindicating the plaintiff’s character by a verdict of the jury that establishes the falsity of the defamatory matter.

W. Page Keeton et al., Prosser and Keeton on Torts § 116A, at 845 (5th ed. 1984). Also, individuals may recover nominal damages for trespass to land, even though the trespasser’s “presence on the land causes no harm to the land [or] its possessor....” Restatement (Second) of Torts § 163 & comments d, e (1965).

The district court therefore properly concluded in its 2010 order:

The use of “any damages” suggests strongly Congressional intent that recovery be available for damages even if they do not amount to ... substantial economic damages.... Requiring a plaintiff who can [show that the copyright holder knowingly misrepresented its subjective good faith] to demonstrate in addition not only that she suffered damages but also that those damages were economic and substantial would vitiate the deterrent effect of the statute.

Lenz v. Universal Music Corp., 2010 WL 702466, at *10 (N.D.Cal., Feb. 25, 2010). Relying on this opinion, the Southern District of Florida held the same. Hotfile, 2013 WL 6336286, at *48 (“The Court observes that the quantity of economic damages to Hotfile’s system is necessarily difficult to measure with precision and has led to much disagreement between the parties and their experts. Notwithstanding this difficulty, the fact of injury has been shown, and Hotfile’s expert can provide the jury with a non-speculative basis to assess damages.”).

We agree that Lenz may vindicate her statutorily created rights by seeking nominal damages. Because a jury has not yet determined whether Lenz will prevail at trial, we need not decide the scope of recoverable damages, i.e., whether she may recover expenses following the initiation of her § 512(f) suit or pro bono costs and attorneys’ fees, both of which arose as a result of the injury incurred.

VI

Copyright holders cannot shirk their duty to consider — in good faith and prior to sending a takedown notification — whether allegedly infringing material constitutes fair use, a use which the DMCA plainly contemplates as authorized by the law. That this step imposes responsibility on copyright holders is not a reason for us to reject it. We affirm the district court’s order denying the parties’ cross-motions for summary judgment.

AFFIRMED.

Notes and questions

(1) What is the central holding of the court regarding a copyright holder’s obligations before sending a DMCA takedown notice, and why does the court reject Universal’s argument that fair use is merely an “affirmative defense”?

In Lenz v. Universal Music Corp., 815 F.3d 1145 (9th Cir. 2015), the Ninth Circuit held that because the fair use of a copyrighted work is indeed “authorized by the law” a person may knowingly materially misrepresent under Section 512(f) by making a statement in support of a 512(c) takedown notice that it has “a good faith belief that use of the material … is not authorized by the copyright owner, its agent, or the law” when that person has not considered the application of the fair use doctrine.

Since the fair use of a copyrighted work is authorized by law, the court concluded (at 1154) that

Universal faces liability if it knowingly misrepresented in the takedown notification that it had formed a good faith belief the video was not authorized by the law, i.e., did not constitute fair use.

In other words, before issuing a takedown notice, a rightsholder must at least form a view about whether the accused work is infringing, and that process includes forming a view as to whether the accused work is fair use.

Was the court correct in characterizing fair use as a right?

The argument is that fair use is no mere defense, such as laches or lack of personal jurisdiction; rather, fair use is a fundamental part of the copyright system that confers rights on the public and defines the outer limits of the copyright owner’s enumerated exclusive rights. This view seems inescapable based on the text of section 107: “Notwithstanding the provisions of sections 106 and 106A, the fair use of a copyrighted work . . . is not an infringement of copyright.” The fact that, procedurally, fair use must usually be pleaded as a defense does not alter its substance. As the court stated, “fair use is not just excused by the law, it is wholly authorized by the law.”

(2) According to the court, what is the difference between the “actual knowledge” standard and the “willful blindness” standard for Section 512(f) liability, and why did Lenz fail to proceed under the willful blindness theory?

(3) What type of damages does the court hold are recoverable under Section 512(f), and how does the court’s interpretation differ from Universal’s argument about “actual monetary loss”?

(4) Note that Circuit Judge M. Smith disagreed with the majority as to whether Lenz was entitled to summary judgment. The majority held that whether Universal’s actions were sufficient to form a subjective good faith belief about the video’s fair use or lack thereof presented a triable issue of fact. Smith saw the issue differently:

Universal admittedly did not consider fair use before notifying YouTube to take down Lenz’s video. It therefore could not have formed a good faith belief that Lenz’s video was infringing, and its notification to the contrary was a knowing material misrepresentation. Accordingly, I would hold that Lenz is entitled to summary judgment.

(5) The version of the Lenz decision extracted above is a little different to the Ninth Circuit’s original decision. As Dan Burk summarizes in his 2019 University of Chicago Law Review article, Algorithmic Fair Use, …

But clearly with the use of automated detection and removal algorithms in mind, the court continued: “We note, without passing judgment, that the implementation of computer algorithms appears to be a valid and good faith middle ground for processing a plethora of content while still meeting the DMCA’s requirements to somehow consider fair use.”

Perhaps not surprisingly, the court later withdrew this particular passage of dicta from the published opinion. The record label’s copyright enforcement search and judgment in Lenz was done manually, and it is unclear whether fair use consideration can in fact be automated.

The critical question in the wake of Lenz is whether rightsholders can rely on the same algorithms they use to identify potential infringement to make a judgment about fair use. As many have noted, identifying fair use is a hard problem for any automated system. For more see Matthew Sag, Internet Safe Harbors and the Transformation of Copyright Law, 93 Notre Dame Law Review 499 (2017), Dan L. Burk, Algorithmic Fair Use, 86 University of Chicago Law Review 283 (2019).

(6) In Internet Safe Harbors and the Transformation of Copyright Law, Matthew Sag argues:

… the Ninth Circuit’s decision in Lenz may have ramifications for the broader public debate on the future of fair use in the United States and overseas. Interest groups advocating for the abolition of fair use, or for a scaling back of the doctrine, frequently buttress their opposition with the argument that fair use is fundamentally uncertain and unpredictable. If fair use doctrine were genuinely as volatile as many insist, then it seems unlikely that a rightsholder could rely on an algorithm to identify potential fair uses without risking section 512(f) liability. Consequently, it is very hard to see how rightsholders’ notice-and-takedown operations could ever scale up to deal with the massive volume of online infringement. But then again, if a rightsholder truly believes that fair use is fundamentally uncertain, could it even attest to its good faith belief that an accused work is not “authorized by ... law” in an individual case, as the statute requires? If I assume that a coin is equally weighted between heads and tails, I cannot in good faith express the belief that it will land on heads. Following Lenz, the radical uncertainty critique of fair use seems to pose a problem for rightsholders. The easiest way for copyright owner representatives such as the Recording Industry Association of America (RIAA) and the Motion Picture Association of America (MPAA) to get out of this conundrum would be to articulate and defend their views on the scope of fair use, rather than simply throwing their hands in the air and pronouncing the whole question an unknowable mystery.

Comparative: European Union Internet safe harbors

The European Union first adopted internet safe harbors in the 2000 E-Commerce Directive. Like the DMCA’s Section 512, these rules were designed to shield online intermediaries from liability for user-posted content—so long as they acted as passive conduits, stored material at a user’s direction, and removed infringing works when notified. Those provisions, Articles 12 to 14 of the E-Commerce Directive, have since been replaced by Articles 4 to 6 of the Digital Services Act, which carries the same three-part structure forward largely unchanged. In practice, the safe harbors covered three main functions:

  • Mere conduit – passing along data without altering it;

  • Caching – temporary storage for efficiency; and

  • Hosting – long-term storage at the request of users.

As in the DMCA, providers were not subject to a general obligation to monitor all user activity. However, the EU framework lacked a formal “counter-notice” process, and implementation varied among member states.

By 2019, critics argued that these safe harbors gave large platforms like YouTube too much leverage over rightsholders, especially in music licensing. This “value gap” concern led to the Digital Single Market Directive (DSM Directive), and its most controversial feature—Article 17. Article 17 changes the safe harbor model for “online content-sharing service providers”—profit-oriented platforms whose main purpose is to host and give public access to large amounts of copyrighted works uploaded by users. For these services, the old “hosting” safe harbor no longer applies. Instead, platforms are directly liable for infringing uploads unless they can show that they have:

  • Made best efforts to obtain licenses from rightsholders;

  • Made best efforts to block unlicensed works once identified; and

  • Acted quickly to remove infringing material and prevent its re-upload.

This shifts the regime from reactive notice and takedown to proactive notice and stay-down. While the directive does not explicitly require “upload filters,” in practice most large platforms will need automated content-recognition systems to comply.

Article 17 also includes safeguards. Member states must ensure that filtering does not block lawful uses, such as quotation, criticism, review, parody, and similar exceptions. Platforms must provide complaint and dispute-resolution procedures, and some small or new services get lighter obligations.

As of mid-2025, the EU has not fully closed the “value gap” that Article 17 of the Digital Single Market Directive was intended to address. The provision aimed to rebalance bargaining power between online platforms and copyright holders, particularly in the music sector, by making platforms directly liable for infringing user uploads unless they obtained licenses or implemented robust prevention measures. While some member states—such as France, Germany, the Netherlands, and Italy—have fully implemented Article 17, others have delayed or only partially transposed it into national law, prompting infringement proceedings by the European Commission. This uneven implementation has resulted in a fragmented legal landscape where the impact on rights holders varies significantly across the EU. In jurisdictions where enforcement is more developed, music rights holders have seen increased licensing activity, often through collective management organizations, but visual artists and smaller creators have experienced fewer tangible benefits.

Practical and legal challenges continue to complicate the Directive’s effectiveness. Platforms have turned to automated content-recognition systems, such as YouTube’s Content ID, to meet compliance obligations, but these tools raise concerns about over-blocking lawful material, lack of transparency, and burdens on smaller services. The design of Article 17 has also been criticized for lacking a clear framework to measure whether the value gap has actually narrowed, and for relying heavily on assumptions about the market power of dominant platforms. While the law has clearly shifted the balance toward more active licensing and monitoring, the combination of inconsistent national implementation, technological and legal uncertainties, and sector-specific disparities means the value gap remains only partially addressed, with its long-term resolution still uncertain.

Other EU laws reinforce and constrain these obligations. In effect since 2018, the General Data Protection Regulation (GDPR) sets strict limits on the collection, storage, and use of personal data. Any filtering or monitoring system used to enforce Article 17 must comply with GDPR principles—such as data minimization, transparency, and security. This means copyright enforcement tools cannot process user data unnecessarily or without a lawful basis.

The EU AI Act (taking effect in stages beginning in 2025) regulates artificial intelligence systems, including some used for content filtering and recommendation. Systems that significantly affect users’ rights—such as filters that may block lawful expression—could be classified as “high-risk,” triggering extra transparency, accuracy, and human oversight requirements.

When does a platform stop merely hosting?

The hosting safe harbor has always depended on the platform being, in some sense, neutral about what it stores. In June 2026 the Grand Chamber of the Court of Justice gave that requirement real teeth. In Joined Cases C-188/24 WebGroup Czech Republic and NKL Associates and C-190/24 Coyote System, decided on 16 June 2026, the Court held that a provider which controls the information it stores falls outside the hosting exemption — and, critically, that this is so even where the provider never subjectively becomes aware of the material because the processing is entirely automated. Control of that kind may be exercised through the algorithm the provider uses to organize and distribute what it holds.

That is a significant narrowing. On the older understanding, a platform lost neutrality by having actual knowledge of specific content, which is why automation was protective: what no human at the company had seen, the company could not be said to know. After Coyote System, the architecture itself can be disqualifying, regardless of knowledge.

It is worth setting this alongside Mavrix and McGucken. American courts and the Court of Justice have arrived at more or less the same question — at what point does a platform’s own organization of user material stop being storage at the direction of a user? — from opposite directions. The United States gets there through the statutory phrase “at the direction of a user” and the separate “right and ability to control” condition, developed case by case on the facts of moderation and curation. The European Union gets there through a general principle of neutrality now applied to algorithmic control. Neither system has settled how much curation is too much. But note which way each is moving: § 512(c) has been read to tolerate a good deal of moderation, as Athos shows, while the European position has just tightened. Convergence is not the same as agreement.